Added additional CSRF hardening in com_installer actions in the backend.
Joomla! CMS versions 2.5.0 through 3.8.12
Upgrade to version 3.8.13
The JSST at the Joomla! Security Centre.
In case that an attacker gets access to the mail account of an user who can approve admin verifications in the registration process he can activate himself.
Joomla! CMS versions 1.5.0 through 3.8.12
Inadequate checks on the tags search fields can lead to an access level violation.
Joomla! CMS versions 3.1.0 through 3.8.12
Joomla’s com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled access of Administrator-level users to access com_joomlaupdate and trigger a code execution.
Joomla! CMS versions 2.5.4 through 3.8.12
Inadequate checks in com_contact could allowed mail submission in disabled forms.