Junglewise Threat Intelligence

CVE-2026-30894: Joomla! CMS XSS in content history component

CVE-2026-30894 · Severity: info · CVSS 6.9 · Published 2026-05-26

Technologies: Joomla! Project Joomla! CMS. Vendors: Joomla! Project.

Executive brief

A vulnerability exists in the Joomla! Content Management System, which is used to build and manage websites. An attacker with high-level administrative privileges could inject malicious scripts into the content history component, potentially leading to unauthorized actions or data theft when other administrators view the history. This could compromise the integrity of the website management interface.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Joomla! CMS 'com_contenthistory' component due to improper neutralization of input during web page generation (CWE-79). The root cause is a lack of output escaping when displaying content history records. An attacker with high privileges (PR:H) can inject malicious scripts that execute in the context of another user's browser session, typically requiring some form of user interaction (UI:P). This affects Joomla! versions 3.0.0 through 5.4.5 and 6.0.0 through 6.1.0. The issue is resolved in versions 5.4.6 and 6.1.1.

Affected products

  • Joomla! Project Joomla! CMS 3.0.0-5.4.5, 6.0.0-6.1.0

Timeline

  • 2026-04-01: other: Reported to vendor
  • 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
  • 2026-05-26: disclosed: Public advisory published

References