In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate escaping of file and folder names leads to XSS vulnerabilities in the template manager component.
We have discovered 129,929 live websites that are affected by CVE-2017-7987.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 129,929 live websites (97% of Joomla install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 45 versions ( 35% of all versions) |
| 7,185 websites | |
| 36,717 websites | |
| 11,621 websites | |
| 7,103 websites | |
| 7,017 websites | |
| 5,246 websites | |
| 5,088 websites | |
| 4,612 websites | |
| 4,286 websites | |
| 3,729 websites |
| .com | 28,248 websites |
| .it | 24,434 websites |
| .ru | 9,661 websites |
| .nl | 3,975 websites |
| .de | 3,709 websites |
| .se | 3,141 websites |
| .org | 3,110 websites |
| .cz | 2,980 websites |
| .co.uk | 2,769 websites |
| .net | 2,592 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | **,*** | ||
| ************.com | **,*** | ||
| ************.com | **,*** | ||
| *********************.com | **,*** | ||
| *****.org | **,*** | ||
| ********.com | **,*** | ||
| *****.it | **,*** | ||
| *********.com | **,*** | ||
| ******.cz | **,*** | ||
| *******.ru | **,*** |