Description
An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.
Remediation
References
Related Vulnerabilities
WordPress Plugin Multi Plugin Installer Arbitrary File Disclosure (1.1.0)
WordPress Plugin Abandoned Cart Lite for WooCommerce SQL Injection (1.8)
MySQL CVE-2020-2930 Vulnerability (CVE-2020-2930)
Jboss EAP Files or Directories Accessible to External Parties Vulnerability (CVE-2021-3717)
WordPress Plugin Elementor Website Builder Cross-Site Scripting (3.5.5)