Executive brief
Joomla!, a popular website management system, contains a security flaw that could allow high-privileged users to inject malicious scripts into the website. If exploited, this could lead to unauthorized actions being performed in the context of another user's session, potentially compromising sensitive data or site integrity. Organizations should update their Joomla! installations to the latest patched versions to mitigate this risk.
Technical details
A cross-site scripting (XSS) vulnerability exists in Joomla! CMS versions 3.0.0 through 5.4.5 and 6.0.0 through 6.1.0. The issue stems from inadequate content filtering within the 'checkAttribute' methods of the Joomla! Framework. An attacker with high privileges (PR:H) can exploit this by injecting malicious scripts that are executed when a victim interacts with affected components. This is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation). The vulnerability has been addressed in Joomla! CMS versions 5.4.6 and 6.1.1.
Affected products
- Joomla! Project Joomla! CMS 3.0.0-5.4.5, 6.0.0-6.1.0
Timeline
- 2026-04-21: other: Reported date
- 2026-05-26: patched: Fixed in versions 5.4.6 and 6.1.1
- 2026-05-26: disclosed: NVD publication date