CVE-2023-23752
KEVMEDIUM 5.3EPSS 99.8%
An issue was discovered in Joomla! 4.0.0 through 4.2.7. An improper access check allows unauthorized access to webservice endpoints.
- CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - CVSS v3.1
- 5.3 MEDIUM
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N - EPSS
- 99.83% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2024-01-08
- Nuclei
- medium
- Published
- 2023-02-16
- Updated
- 2026-02-26
Proof-of-concept exploits (62)
- 0x0jr/HTB-Devvortex-CVE-2023-2375-PoC0★ · 2024-07-03
- 0xNahim/CVE-2023-237525★ · 2023-03-26
- 0xVoodoo/CVE-2023-237520★ · 2026-05-01
- 0xVoodoo/PoCs0★ · 2026-05-01
- 0xWhoami35/CVE-2023-237522★ · 2025-03-29
- 0xx01/CVE-2023-237520★ · 2024-04-28
- ATIGNONWilliam/-Joomla-v4.2.8---Divulgation-d-informations-non-authentifi-es0★ · 2023-06-08
- Acceis/exploit-CVE-2023-2375294★ · 2023-12-27
- AlissoftCodes/CVE-2023-237521★ · 2024-04-25
- AlissonFaoli/CVE-2023-237521★ · 2024-04-25
- Aureum01/CVE-2023-237520★ · 2024-08-11
- BearClaw96/Joomla-v4.x-Unauthenticated-information-disclosure1★ · 2023-11-27
- C1ph3rX13/CVE-2023-237520★ · 2023-12-25
- Fernando-olv/Joomla-CVE-2023-237524★ · 2023-12-04
- GhostToKnow/CVE-2023-237522★ · 2023-03-10
- Jenderal92/Joomla-CVE-2023-237520★ · 2026-05-30
- JeneralMotors/CVE-2023-237520★ · 2023-12-18
- JohnDoeAnonITA/CVE-2023-237521★ · 2024-05-03
- K3ysTr0K3R/CVE-2023-23752-EXPLOIT18★ · 2026-02-01
- Ly0kha/Joomla-CVE-2023-23752-Exploit-Script0★ · 2023-11-29
- MrP4nda1337/CVE-2023-237520★ · 2023-07-26
- N3rdyN3xus/CVE-2023-237521★ · 2024-05-31
- NyxByt3/CVE-2023-237521★ · 2024-05-31
- Pari-Malam/CVE-2023-2375234★ · 2023-07-24
- Pari-Malam/DorkerW-CVE-2023-2375234★ · 2023-07-24
- Pushkarup/CVE-2023-237521★ · 2023-10-25
- Rival420/CVE-2023-237520★ · 2024-02-19
- Saboor-Hakimi/CVE-2023-237523★ · 2023-02-18
- Sp3c73rSh4d0w/CVE-2023-237521★ · 2024-05-31
- Sweelg/CVE-2023-237524★ · 2023-06-16
- ThatNotEasy/CVE-2023-2375234★ · 2023-07-24
- UKGovernmentBEIS/doomla6★ · 2025-09-28
- Vulnmachines/joomla_CVE-2023-237523★ · 2023-02-20
- Youns92/Joomla-v4.2.8---CVE-2023-237526★ · 2023-11-28
- YusinoMy/CVE-2023-237522★ · 2023-02-18
- adhikara13/CVE-2023-237527★ · 2023-04-04
- adriyansyah-mf/CVE-2023-237520★ · 2023-03-07
- blacks1ph0n/CVE-2023-237522★ · 2023-11-03
- cybernetwiz/CVE-2023-237522★ · 2023-11-03
- gibran-abdillah/CVE-2023-237527★ · 2023-03-14
- gunzf0x/CVE-2023-237520★ · 2023-12-19
- h3x0v3rl0rd/CVE-2023-237521★ · 2024-05-31
- h3xcr4ck3r/CVE-2023-237521★ · 2024-05-31
- hadrian3689/CVE-2023-23752_Joomla0★ · 2023-12-11
- ibaiw/joomla_CVE-2023-237522★ · 2023-03-02
- ifacker/CVE-2023-23752-Joomla3★ · 2023-02-23
- karthikuj/CVE-2023-23752-Docker4★ · 2023-03-25
- keyuan15/CVE-2023-2375212★ · 2023-03-03
- malionnn/-Joomla-v4.2.8---Divulgation-d-informations-non-authentifi-es0★ · 2023-06-08
- mariovata/CVE-2023-23752-Python0★ · 2024-04-15
- n3rdh4x0r/CVE-2023-237521★ · 2024-05-31
- r3dston3/CVE-2023-237521★ · 2023-11-30
- raystr-atearedteam/CVE2023-237520★ · 2023-12-11
- shellvik/CVE-2023-237520★ · 2023-12-29
- svaltheim/CVE-2023-237520★ · 2023-11-30
- sw0rd1ight/CVE-2023-237520★ · 2023-02-18
- wangking1/CVE-2023-23752-poc1★ · 2023-02-23
- yTxZx/CVE-2023-237520★ · 2023-10-20
- z3n70/CVE-2023-2375217★ · 2023-02-24
- BardLaudian/CVE-2023-23752
- Anekant-Singhai/Exploits
- k8gege/Ladon