Junglewise Threat Intelligence

CVE-2026-48949: Joomla! CMS XSS in MFA management views

CVE-2026-48949 · Severity: info · CVSS 5.9 · Published 2026-07-07

Technologies: Joomla! Project Joomla! CMS. Vendors: Joomla! Project.

Executive brief

Joomla! CMS, a popular platform for building and managing websites, contains a security flaw in its Multi-Factor Authentication (MFA) management interface. An attacker with high-level administrative privileges could inject malicious scripts into these management views. If successful, this could allow the attacker to execute unauthorized actions in the context of another user's session, potentially compromising sensitive administrative functions.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Joomla! CMS versions 4.2.0 through 5.4.6 and 6.0.0 through 6.1.1. The flaw is located in the MFA method management views, where a lack of proper input validation allows for the injection of malicious scripts. Exploitation requires an attacker to have high privileges (PR:H) and involves user interaction (UI:P) from another administrator. Successful exploitation can lead to a high impact on confidentiality and integrity within the management interface. The issue has been addressed in Joomla! CMS versions 5.4.7 and 6.1.2.

Affected products

  • Joomla! Project Joomla! CMS业务 4.2.0-5.4.6, 6.0.0-6.1.1

Timeline

  • 2026-05-07: disclosed: Vulnerability reported to Joomla! Project
  • 2026-07-07: patched: Fixed in versions 5.4.7 and 6.1.2
  • 2026-07-07: advisory

References