The Session package 1.x before 1.3.1 for Joomla! Framework allows remote attackers to execute arbitrary code via unspecified session values.
packagist package report
Is joomla/session safe?
1 known vulnerability, worst severity HIGH.
// reach
0 direct dependencies
none carry a known advisory
0 packages depend on it
an advisory here reaches each of them
Create a free accountfor every dependency path, dependent and what to upgrade
// ai model usage
Tracked for PyPI packages. HuggingFace models declare Python dependencies, so packagist packages are not covered.
cvss
0.0
high
severity band, no base score published
epss
0.00%
high
chance of exploitation in 30 days, 95th percentile of all CVEs
xyz score
0.0
medium
CyberXYZ composite, a working exploit is published
fig. 01 — GHSA-wwfh-28hx-w2r2, the advisory selected below
// 1 advisories
Checked 2026-10-04 at 01:13 UTC. The most recent advisory here was published 2022-05-17. Updated continuously from NVD, GHSA, OSV and CNA feeds.