cvedb.io
CVE-2016-8870
HIGH · CVSS 8.1
EPSS exploitation probability: 0%
Published 2016-11-04T21:59:08.677 · Last modified 2026-06-17T00:55:06.673

Summary

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.

Affected products

joomla — joomla\!

Does this affect you?

Add your gear to cvedb and we'll alert you only when joomla ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.