Junglewise Threat Intelligence

CVE-2026-25901: Joomla! CMS XSS in multilingual associations component

CVE-2026-25901 · Severity: info · CVSS 6.9 · Published 2026-05-26

Technologies: Joomla CMS. Vendors: Joomla.

Executive brief

A vulnerability exists in Joomla! CMS, a popular platform used for building and managing websites. The flaw is located in the component responsible for managing content across different languages. If exploited, an attacker could inject malicious scripts into the website's administrative interface, potentially leading to unauthorized actions or the theft of sensitive session information from other administrators.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Joomla! CMS 'com_associations' component. The issue stems from a lack of proper output escaping when rendering content within the multilingual associations interface. An attacker with high-level administrative privileges can inject malicious JavaScript that executes in the context of another user's browser session when they view the affected component. This could lead to session hijacking or unauthorized administrative actions. The vulnerability affects Joomla! versions 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0, and is resolved in versions 5.4.6 and 6.1.1.

Affected products

  • Joomla! CMS 4.0.0 - 5.4.5, 6.0.0 - 6.1.0

Timeline

  • 2026-04-01: disclosed: Vulnerability reported to Joomla! Security Centre
  • 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
  • 2026-05-26: advisory: Public advisory published by Joomla! Project

References