In Joomla! before 3.9.19, lack of input validation in the heading tag option of the "Articles - Newsflash" and "Articles - Categories" modules allows XSS.
{
"versions": [
{
"introduced": "3.0.1"
},
{
"fixed": "3.9.19"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0-NA"
},
{
"introduced": "0"
},
{
"last_affected": "3.0.0-beta1"
}
]
}