The Joomla PHP-based content management system has the following vulnerabilities:
There are multiple cross-site request forgery vulnerabilities.
There is one cross-site scripting vulnerability.
There is a vulnerability where remote authenticated administrators can
promote arbitrary users to the administrator group, violating the intended
security model.
There is a registered user privilege escalation vulnerability.