Executive brief
A security vulnerability exists in the Joomla! CMS search component (com_finder) that could allow an authorized user with high-level permissions to perform unauthorized database queries. This could lead to the exposure of sensitive information stored in the website's database. Organizations using affected versions of Joomla! should update to the latest patched versions to prevent potential data theft.
Technical details
A blind SQL injection vulnerability exists in the Joomla! CMS 'com_finder' component due to improperly constructed filter clauses in search queries. The flaw (CWE-89) allows a remote attacker with high administrative privileges (PR:H) to execute arbitrary SQL commands against the backend database. While the attack requires authentication, it can be used to extract sensitive data through blind injection techniques. The issue affects Joomla! versions 5.4.0 through 5.4.5 and 6.0.0 through 6.1.0, and has been addressed in versions 5.4.6 and 6.1.1.
Affected products
- Joomla! CMS 5.4.0-5.4.5, 6.0.0-6.1.0
Timeline
- 2026-03-31: disclosed: Reported by Adrian Junge
- 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
- 2026-05-26: advisory