CVE-2018-11321

An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option.


We have discovered 211,306 live websites that are affected by CVE-2018-11321.

Run a Free Instant Scan




Affected Software

Product  Joomla
Category Content Management System
Vulnerable Domains211,306 live websites (99% of Joomla install base)
Vulnerable Versions
  • from 0 through 3.8.8
Vulnerable Versions Count60 versions ( 58% of all versions)



Details

  • Published - May 22, 2018
  • Updated - Aug 5, 2024

Website Distribution by Country

Number of websites using CVE-2018-11321
United States12,085 websites



Italy52,572 websites
Russia15,897 websites
Poland13,770 websites
Germany13,534 websites
GB13,357 websites
Iran8,316 websites
Netherlands7,877 websites
Kazakhstan6,817 websites
South Africa6,703 websites

Website Distribution by TLD

Number of websites using CVE-2018-11321
.com51,052 websites
.it34,239 websites
.ru13,329 websites
.pl9,725 websites
.co.uk6,502 websites
.org5,827 websites
.de5,324 websites
.net4,445 websites
.nl4,114 websites
.se3,379 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2018-11321

Top websites that are affected by CVE-2018-11321. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****************.de Germany*,***
*******.**.ca Canada*,***
*****.com Italy**,***
***********.**.za South Africa**,***
**************.se Sweden**,***
***************.com Italy**,***
*********.com GB**,***
************.com United States**,***
************.com Germany**,***
*********************.com United States**,***
See full domain list

FAQ

A total of 211,306 websites have been identified as vulnerable to CVE-2018-11321, based on global website indexing conducted by WebTechSurvey.
The Joomla is affected by the CVE-2018-11321 vulnerability.
Joomla versions up to and including 3.8.8 are vulnerable to CVE-2018-11321.