An issue was discovered in Joomla! before 3.9.4. The media form field lacks escaping, leading to XSS.