Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.
{ "severity": "Medium", "cpes": [ "cpe:2.3:a:joomla:joomla!:*:*:*:*:*:*:*:*" ] }