Lack of output escaping leads to a XSS vector in the pagebreak plugin.
We have discovered 4,670 live websites that are affected by CVE-2025-63083.
| Product | |
| Category | Content Management System |
| Vulnerable Domains | 4,670 live websites (2.10% of Joomla install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 39 versions ( 38% of all versions) |
| 588 websites | |
| 1,275 websites | |
| 415 websites | |
| 321 websites | |
| 263 websites | |
| 256 websites | |
| 234 websites | |
| 140 websites | |
| 135 websites | |
| 116 websites |
| .de | 1,041 websites |
| .com | 913 websites |
| .nl | 237 websites |
| .org | 233 websites |
| .it | 226 websites |
| .fr | 225 websites |
| .ru | 219 websites |
| .ch | 206 websites |
| .net | 117 websites |
| .at | 112 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ***********.com | **,*** | ||
| ******.**.il | **,*** | ||
| **.******.org | **,*** | ||
| *********************.com | ***,*** | ||
| *****************.***.pl | ***,*** | ||
| **************.com | ***,*** | ||
| ****.org | ***,*** | ||
| ****.***.ph | ***,*** | ||
| ******.net | ***,*** | ||
| ***************.************.de | ***,*** |
FAQ