Junglewise Threat Intelligence

CVE-2026-25900: Joomla! CMS cross-site scripting in feed modules

CVE-2026-25900 · Severity: info · CVSS 6.9 · Published 2026-05-26

Technologies: Joomla! Project Joomla! CMS. Vendors: Joomla! Project.

Executive brief

A vulnerability exists in the Joomla! CMS feed modules, which are used to display external content feeds on a website. An attacker with high-level administrative privileges could inject malicious scripts that execute in the browsers of other users. This could lead to unauthorized actions being performed on behalf of those users or the theft of sensitive session information.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Joomla! CMS versions 3.0.0 through 5.4.5 and 6.0.0 through 6.1.0. The flaw is caused by insufficient output escaping within the feed modules. An attacker with high privileges (PR:H) can exploit this by injecting malicious payloads into feed configurations, which are then executed when a user views the affected page. This can result in the execution of arbitrary JavaScript in the context of the victim's session. The issue is addressed in Joomla! CMS versions 5.4.6 and 6.1.1.

Affected products

  • Joomla! Project Joomla! CMS 3.0.0-5.4.5, 6.0.0-6.1.0

Timeline

  • 2026-03-28: disclosed: Vulnerability reported to the Joomla! Security Centre.
  • 2026-05-26: patched: Fixed versions 5.4.6 and 6.1.1 released.
  • 2026-05-26: advisory: Official security announcement published.

References