CVE-2020-15696
An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.
Date published : 2020-07-15
https://developer.joomla.org/security-centre/822-20200705-core-escape-mod-random-image-link.html