• Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Versions: 2.5.0 - 3.9.27
  • Exploit type: Incorrect Session Handling
  • Reported Date: 2019-02-08
  • Fixed Date: 2021-07-06
  • CVE Number: CVE-2021-26037


Various CMS functions did not properly termine existing user sessions when a user's password was changed or the user was blocked.

Affected Installs

Joomla! CMS versions 2.5.0 - 3.9.27


Upgrade to version 3.9.28


The JSST at the Joomla! Security Centre.

Reported By: Carsten Schmitz, Atik Islam, Dennis Hermatski, Muhammad Hussain, th3lawbreaker, Hoang Kien