- Project: Joomla!
 - SubProject: CMS
 - Impact: Low
 - Severity: Low
 - Versions: 2.5.0 through 3.9.1
 - Exploit type: XSS
 - Reported Date: 2018-December-04
 - Fixed Date: 2019-January-15
 - CVE Number: CVE-2019-6261
 
Description
Inadequate escaping in com_contact leads to a stored XSS vulnerability
Affected Installs
Joomla! CMS versions 2.5.0 through 3.9.1
Solution
Upgrade to version 3.9.2
Contact
The JSST at the Joomla! Security Centre.