An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current language might contain unescaped HTML special characters. This may lead to reflective XSS via injection of arbitrary parameters and/or values on the current page URL.
We have discovered 130,057 live websites that are affected by CVE-2018-12711.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 130,057 live websites (97% of Joomla install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 59 versions ( 45% of all versions) |
| 7,196 websites | |
| 36,731 websites | |
| 11,637 websites | |
| 7,120 websites | |
| 7,017 websites | |
| 5,249 websites | |
| 5,090 websites | |
| 4,612 websites | |
| 4,287 websites | |
| 3,729 websites |
| .com | 28,275 websites |
| .it | 24,442 websites |
| .ru | 9,674 websites |
| .nl | 3,976 websites |
| .de | 3,722 websites |
| .se | 3,141 websites |
| .org | 3,113 websites |
| .cz | 2,984 websites |
| .co.uk | 2,770 websites |
| .net | 2,597 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****.com | **,*** | ||
| ************.com | **,*** | ||
| ************.com | **,*** | ||
| *********************.com | **,*** | ||
| *****.org | **,*** | ||
| ********.com | **,*** | ||
| *****.it | **,*** | ||
| *********.com | **,*** | ||
| ******.cz | **,*** | ||
| *******.ru | **,*** |