Skip to main content

CVE-2016-8870

8.1
HIGHCVSS v3.1 Base Score
91.61%
HIGH RiskEPSS (100th percentile)

The register method in the UsersModelRegistration class in controllers/user.php in the Users component in Joomla! before 3.6.4, when registration has been disabled, allows remote attackers to create user accounts by leveraging failure to check the Allow User Registration configuration setting.

Published: 11/4/2016
Modified: 4/12/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.1HIGH

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

91.61%HIGH Exploitation Risk
100th percentile

This vulnerability has a 91.61% probability of being exploited in the next 30 days, ranking higher than 100% of all scored CVEs.

Related Vulnerabilities