CVE-2022-23795 | [20220303] - Core - User row are not bound to a authentication mechanism
An issue was discovered in Joomla! 2.5.0 through 3.10.6 & 4.0.0 through 4.1.0. A user row was not bound to a specific authentication mechanism which could under very special circumstances allow an account takeover.
Conclusion & alert: CVE-2022-23795 is rated Moderate Risk (61.3/100): CVSS Critical severity, with medium exploitation likelihood (EPSS 1.07%).Core evidence: EPSS rose +1.06% over the last day, indicating growing attacker interest.Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
Exploit prediction scoring system (EPSS) score for CVE-2022-23795
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).