What's in 3.8.13? Joomla 3.8.13 includes 5 security vulnerability fixes: Low Priority - Core - Hardening com_contact contact form (affecting Joomla 2.5.0 through 3.8.12) More information » Low Priority - Core - Inadequate default access level for com_joomlaupdate (affecting Joomla 2.5.4 through 3.8.12) More information » Low Priority - Core - Access level Violation in com_tags (affecting Joomla 3.1.0 through 3.8.12) More information » Low Priority - Core - ACL Violation in com_users for the admin verification (affecting Joomla 1.5.0 through 3.8.12) More information » Low Priority - Core - CSRF hardening in com_installer (affecting Joomla 2.5.0 through 3.8.12) More information » Please see the documentation wiki for the security notes about this release.
Даже не знаю что написать. Известно о проблеме с уязвимостью еще с 2017 года ,а исправили в 2018 . Боле чем уверен, что Джумла 1.5 еще будет у многих использоваться без последствий.