An issue was discovered in Joomla! before 3.9.15. A missing CSRF token check in the LESS compiler of com_templates causes a CSRF vulnerability.
We have discovered 211,377 live websites that are affected by CVE-2020-8420.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 211,377 live websites (99% of Joomla install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 78 versions ( 76% of all versions) |
| 10,551 websites | |
| 56,270 websites | |
| 15,676 websites | |
| 15,373 websites | |
| 13,913 websites | |
| 12,622 websites | |
| 12,395 websites | |
| 7,318 websites | |
| 6,196 websites | |
| 5,928 websites |
| .com | 51,234 websites |
| .it | 37,026 websites |
| .ru | 13,018 websites |
| .pl | 11,005 websites |
| .co.uk | 6,961 websites |
| .org | 5,261 websites |
| .de | 5,019 websites |
| .net | 4,248 websites |
| .nl | 3,688 websites |
| .se | 3,284 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *****************.de | *,*** | ||
| *******.**.ca | *,*** | ||
| *****.com | **,*** | ||
| ***********.**.za | **,*** | ||
| **************.se | **,*** | ||
| ***************.com | **,*** | ||
| *********.com | **,*** | ||
| ************.com | **,*** | ||
| ************.com | **,*** | ||
| *********************.com | **,*** |