CVE-2018-12712

An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" function in PHP. In PHP 5.3, this function validates invalid names as valid, which can result in a Local File Inclusion.


We have discovered 130,057 live websites that are affected by CVE-2018-12712.

Run a Free Instant Scan




Affected Software

Product  Joomla
Category Content Management System
Vulnerable Domains130,057 live websites (97% of Joomla install base)
Vulnerable Versions
  • from 0 through 3.8.8
Vulnerable Versions Count59 versions ( 45% of all versions)



Details

  • Published - Jun 26, 2018
  • Updated - Aug 5, 2024

Website Distribution by Country

Number of websites using CVE-2018-12712
United States7,196 websites



Italy36,731 websites
Russia11,637 websites
Germany7,120 websites
Kazakhstan7,017 websites
GB5,249 websites
Netherlands5,090 websites
South Africa4,612 websites
Serbia4,287 websites
Sweden3,729 websites

Website Distribution by TLD

Number of websites using CVE-2018-12712
.com28,275 websites
.it24,442 websites
.ru9,674 websites
.nl3,976 websites
.de3,722 websites
.se3,141 websites
.org3,113 websites
.cz2,984 websites
.co.uk2,770 websites
.net2,597 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2018-12712

Top websites that are affected by CVE-2018-12712. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.com Italy**,***
************.com United States**,***
************.com Germany**,***
*********************.com United States**,***
*****.org United States**,***
********.com Slovakia**,***
*****.it Italy**,***
*********.com United States**,***
******.cz Czech Republic**,***
*******.ru Russia**,***
See full domain list

FAQ

A total of 130,057 websites have been identified as vulnerable to CVE-2018-12712, based on global website indexing conducted by WebTechSurvey.
The Joomla is affected by the CVE-2018-12712 vulnerability.
Joomla versions up to and including 3.8.8 are vulnerable to CVE-2018-12712.