The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
{ "cpes": [ "cpe:2.3:a:joomla:joomla!:*:*:*:*:*:*:*:*", "cpe:2.3:a:joomla:joomla!:*:*:*:*:elts:*:*:*" ], "severity": "Medium" }