Executive brief
Joomla! CMS, a popular platform for building and managing websites, contains a security flaw in how it handles 'read more' links within content. An attacker with high-level administrative privileges could exploit this to inject malicious scripts into the website. If a site visitor or another administrator views the affected content, the script could execute in their browser, potentially leading to unauthorized actions or data theft.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Joomla! CMS 'com_content' component. The root cause is a failure to properly escape output when generating 'readmore' links. An attacker with high privileges (PR:H) can inject malicious payloads that execute in the context of a user's browser session when they interact with the affected links. The vulnerability affects Joomla! versions 4.0.0 through 5.4.5 and 6.0.0 through 6.1.0. Users are advised to upgrade to versions 5.4.6 or 6.1.1 to remediate the issue.
Affected products
- Joomla! Project Joomla! CMS 4.0.0-5.4.5, 6.0.0-6.1.0
Timeline
- 2026-04-14: other: Reported to vendor
- 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
- 2026-05-26: disclosed: Public disclosure of CVE-2026-30895