In Joomla! before 3.9.19, missing token checks in com_postinstall lead to CSRF.
We have discovered 274,431 live websites that are affected by CVE-2020-13760.
Product | |
Category | Content Management System |
Vulnerable Domains | 274,431 live websites (98.80% of Joomla install base) |
Vulnerable Versions |
|
Vulnerable Versions Count | 101 versions ( 60.12% of all versions) |
![]() | 16,387 websites |
![]() | 66,649 websites |
![]() | 24,831 websites |
![]() | 16,776 websites |
![]() | 14,614 websites |
![]() | 14,503 websites |
![]() | 12,858 websites |
![]() | 11,592 websites |
![]() | 9,251 websites |
![]() | 8,928 websites |
.com | 66,855 websites |
.it | 43,790 websites |
.com.au | 17,073 websites |
.ru | 12,403 websites |
.pl | 9,217 websites |
.co.uk | 9,030 websites |
.org | 7,562 websites |
.de | 7,081 websites |
.nl | 6,916 websites |
.net | 5,926 websites |
Domain | Country | Rank | Contacts |
---|---|---|---|
*****************.de | ![]() | *,*** | |
*******.**.ca | ![]() | *,*** | |
**************.********.com | ![]() | **,*** | |
***********.com | ![]() | **,*** | |
***********.**.za | ![]() | **,*** | |
********.com | ![]() | **,*** | |
***************.com | ![]() | **,*** | |
********.com | ![]() | **,*** | |
*********.com | ![]() | **,*** | |
*****.**.uk | ![]() | **,*** |
FAQ