Joomla! CSRF Vulnerability in User Activation Endpoint

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the admin activation endpoint of the com_users component in Joomla! CMS. This issue arises from a lack of proper validation for CSRF tokens, creating an attack vector that could be exploited.

Impact

Exploitation of this vulnerability allows for Cross-Site Request Forgery attacks, where an attacker could potentially perform actions on behalf of an authenticated user without their consent.

Remediation

Users are advised to upgrade to Joomla! CMS version 6.1.1.

Added: May 26, 2026, 11:19 PM
Updated: May 26, 2026, 11:19 PM

Vulnerability Rating

Custom Algorithm
spread
7.6
impact
2.5
exploitability
6.4
remediation
7.7
relevance
9.6
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.