CVE-2025-63083

Joomla! Core - [20260102] - XSS vector in the pagebreak plugin

Lack of output escaping leads to a XSS vector in the pagebreak plugin.


We have discovered 4,670 live websites that are affected by CVE-2025-63083.

Run a Free Instant Scan




Affected Software

Product  Joomla
Category Content Management System
Vulnerable Domains4,670 live websites (2.10% of Joomla install base)
Vulnerable Versions
  • from 3.9 through 5.4.1
  • from 6 through 6.0.1
Vulnerable Versions Count39 versions ( 38% of all versions)


Common Weakness Enumeration

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')



Details

  • Published - Jan 6, 2026
  • Updated - Jan 6, 2026

Credits

  • peterhulst (finder)

Website Distribution by Country

Number of websites using CVE-2025-63083
United States588 websites



Germany1,275 websites
France415 websites
Italy321 websites
Russia263 websites
Netherlands256 websites
Switzerland234 websites
Poland140 websites
GB135 websites
Austria116 websites

Website Distribution by TLD

Number of websites using CVE-2025-63083
.de1,041 websites
.com913 websites
.nl237 websites
.org233 websites
.it226 websites
.fr225 websites
.ru219 websites
.ch206 websites
.net117 websites
.at112 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-63083

Top websites that are affected by CVE-2025-63083. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
***********.com United States**,***
******.**.il Israel**,***
**.******.org United States**,***
*********************.com United States***,***
*****************.***.pl Poland***,***
**************.com France***,***
****.org Spain***,***
****.***.ph Philippines***,***
******.net United States***,***
***************.************.de Germany***,***
See full domain list

FAQ

CVE-2025-63083 is Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in Joomla
A total of 4,670 websites have been identified as vulnerable to CVE-2025-63083, based on global website indexing conducted by WebTechSurvey.
The Joomla is affected by the CVE-2025-63083 vulnerability.
Joomla versions up to and including 6.0.1 are vulnerable to CVE-2025-63083.