Executive brief
Joomla! CMS, a popular website management platform, contains a security flaw in its template management component. An attacker with high-level administrative privileges could inject malicious scripts into the file management interface. If another administrator views the affected page, the script could execute, potentially leading to unauthorized actions or data theft within the management console.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Joomla! CMS 'com_templates' component within the file management view. The issue stems from a lack of proper output escaping of user-supplied data. An attacker with high privileges (PR:H) can exploit this by injecting malicious scripts that execute in the context of another user's browser session when they interact with the file management interface. The vulnerability affects Joomla! versions 4.0.0 through 5.4.6 and 6.0.0 through 6.1.1. It has been addressed in versions 5.4.7 and 6.1.2.
Affected products
- Joomla! Project Joomla! CMS 4.0.0 - 5.4.6, 6.0.0 - 6.1.1
Timeline
- 2026-05-07: disclosed: Reported to the Joomla! Security Centre
- 2026-07-07: patched: Fixed in versions 5.4.7 and 6.1.2
- 2026-07-07: advisory: NVD and Joomla! Project published advisories