An issue exists in Joomla! 3.0.0 up to and including 3.9.27. Inadequate escaping in the rules field of the JForm API leads to a XSS vulnerability.
joomla joomla\\!