An issue was discovered in Joomla! through 3.9.19. Lack of input filtering and escaping allows XSS attacks in mod_random_image.
https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-7683
https://developer.joomla.org/security-centre/822-20200705-core-escape-mod-random-image-link.html