CVE-2023-23752General(joomla / joomla\!)

HIGHCVSS 5.3 · MEDIUMCISA KEV

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for joomla joomla\! systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.

7.0/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-01-29. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-284

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • joomla\!

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • 6 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • General: 4 classified signals
  • Peaked 5d ago at 1 mentions (2026-02-08); latest day: 1
  • 6 total mentions across 6 days

Affected systems

Vendors
Products
joomla\!

Deep dive

Activity timeline6 mentions / 6d
00111Mentions · 2026-02-08: 1Mentions · 2026-03-10: 1Mentions · 2026-03-16: 1Mentions · 2026-03-23: 1Mentions · 2026-03-31: 1Mentions · 2026-05-22: 1PoC Mentioned / Linked · 2026-03-16: 1Exploit Tool / Code · 2026-03-16: 1Active Exploitation · 2026-03-16: 1Technical Details · 2026-03-16: 1Technical Details · 2026-03-23: 1Technical Details · 2026-03-31: 102-0803-1003-1603-2303-3105-22
Signal classification2 categories
General
466.7%
Exploit
233.3%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-081
Exploit1
2026-03-101
General1
2026-03-161
Exploit1
2026-03-231
General1
2026-03-311
General1
2026-05-221
General1
Full discourse6 posts
  • Himadri Singh@LittleSun4lower
    General

    I just completed Joomify: CVE-2023-23752 room on TryHackMe! Learn how to exploit a Joomla CMS using CVE-2023-23752 and understand various mitigation techniques. https://tryhackme.com/room/joomify?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=66457951599dd28bfb000ded #tryhackme via @tryhackme #tryhackme #learning #consistency

    Post summary

    The tweet announces a TryHackMe training room focused on exploiting CVE-2023-23752, offering learning material but no explicit exploit code, active exploitation evidence, or detailed technical or mitigation information.

    0001067
    14 followersView on X
  • Patrick Roland@DeusLogica
    General

    🔴 EPSS 94.0% | Almost certainly exploitation | medium confidence CVE-2023-23752 (EPSS 94.00%) An issue discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2023-23752 #EPSS #threatintel #CVE #cybersecurity

    Post summary

    The post highlights a Joomla! vulnerability with a high EPSS score, noting an improper access check, but provides no exploit details, active exploitation proof, or patch information.

    1000086
    311 followersView on X
  • TL;DR CTF with Onurcan@CtfWithOG
    Exploit

    4/10 JoomScan fingerprinted Joomla 4.2.6. CVE-2023-23752 → unauthenticated info disclosure. Ran the Ruby exploit: ruby exploit.rb http://dev.devvortex.htb Got DB creds straight from the API: lewis:P4ntherg0t1n5r3c0n##. Zero auth required.

    Post summary

    The text reports exploitation of CVE-2023-23752, an unauthenticated info‑disclosure flaw in Joomla 4.2.6, via a Ruby exploit that successfully extracted database credentials.

    1000072
    5 followersView on X
  • vu1nz🏴‍☠️☢️☠️@offsec97
    Exploit

    I just completed Joomify: CVE-2023-23752 room on TryHackMe! Learn how to exploit a Joomla CMS using CVE-2023-23752 and understand various mitigation techniques. https://tryhackme.com/room/joomify?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=6289b253863325005c062e58 #tryhackme via @tryhackme

    Post summary

    The tweet promotes a TryHackMe training room that teaches exploitation of CVE‑2023‑23752 in Joomla, focusing on learning the exploit and mitigation techniques, but it does not provide any code, tool, or patch details.

    00010101
    694 followersView on X
  • Patrick Roland@DeusLogica
    General

    🔴 EPSS 95.0% | Almost certainly exploitation | medium confidence CVE-2023-23752 (EPSS 95.00%) An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints. Highest risk of all CVEs by exploitation likelihood Source: http://FIRST.org EPSS | Reliability: B Link: https://nvd.nist.gov/vuln/detail/CVE-2023-23752 #EPSS #threatintel #CVE #cybersecurity

    Post summary

    The post highlights a high EPSS score and an improper access check for CVE‑2023‑23752 in Joomla!, but gives no PoC, exploit code, or evidence of active exploitation.

    0000078
    310 followersView on X
  • 317ON13_LIRW@ToTo13ru_xakep
    General

    I just completed Joomify: CVE-2023-23752 room on TryHackMe! Learn how to exploit a Joomla CMS using CVE-2023-23752 and understand various mitigation techniques. https://tryhackme.com/room/joomify?utm_campaign=social_share&utm_medium=social&utm_content=room&utm_source=twitter&sharerId=662fb6411f3680a87baf9e1f #tryhackme via @tryhackme

    Post summary

    The tweet promotes a TryHackMe room on CVE‑2023‑23752, offering educational content on exploitation and mitigation, but provides no concrete technical details, code, or evidence of exploitation.

    0000054
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appjoomlajoomla\!---

Explore more