Description
An issue was discovered in Joomla! before 3.9.21. Lack of escaping in mod_latestactions allows XSS attacks.
Remediation
References
Related Vulnerabilities
WordPress Plugin NS Utilities Unspecified Vulnerability (1.0)
Craft CMS Improper Control of Generation of Code ('Code Injection') Vulnerability (CVE-2021-27903)
WordPress Plugin Permalink Manager Lite Cross-Site Request Forgery (2.2.20.1)
WordPress Plugin WP eCommerce 'cart_messages[]' Parameter Cross-Site Scripting (3.8.6)