Description
In Joomla! before 3.9.19, the default settings of the global textfilter configuration do not block HTML inputs for Guest users.
Remediation
References
Related Vulnerabilities
WordPress Plugin Connections Business Directory Cross-Site Scripting (8.5.8)
WordPress Plugin Gallery-Video Gallery and Youtube Gallery Cross-Site Scripting (1.2.4)
WordPress Plugin Spreadsheet (wpSS) 'ss_id' Parameter SQL Injection (0.61)
WordPress Plugin Social Essentials-Social Stats and Sharing Buttons Cross-Site Scripting (1.3.1)
WordPress Plugin Spam protection, AntiSpam, FireWall by CleanTalk SQL Injection (5.185)