Description
An issue was discovered in Joomla! 3.1.0 through 3.9.23. The lack of escaping of image-related parameters in multiple com_tags views cause lead to XSS attack vectors.
Remediation
References
Related Vulnerabilities
WordPress Plugin FV Flowplayer Video Player Cross-Site Scripting (7.2.0.727)
WordPress Plugin Encrypted Blog Multiple Vulnerabilities (0.0.6.2)
Atlassian Confluence Incorrect Default Permissions Vulnerability (CVE-2017-9505)
WordPress Plugin Widget Settings Importer/Exporter Cross-Site Scripting (1.5.3)