Junglewise Threat Intelligence

CVE-2026-48951: Joomla! CMS XSS in modalreturn layouts

CVE-2026-48951 · Severity: info · CVSS 5.9 · Published 2026-07-07

Technologies: Joomla! Project Joomla! CMS. Vendors: Joomla! Project.

Executive brief

Joomla! CMS is a popular platform used to build and manage websites. A security flaw in how the system handles certain pop-up window layouts could allow an attacker to inject malicious scripts. If successful, this could lead to unauthorized actions being performed in the context of an administrator's session, potentially compromising the website's integrity or data.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Joomla! CMS versions 4.0.0 through 5.4.6 and 6.0.0 through 6.1.1. The issue stems from a lack of proper output escaping within the 'modalreturn' layouts used by various core components. An attacker with high-privileged access (PR:H) could exploit this by injecting malicious scripts that execute when a user interacts with the affected modal interface. This could lead to session hijacking or unauthorized administrative actions. The vulnerability is addressed in versions 5.4.7 and 6.1.2.

Affected products

  • Joomla! Project Joomla! CMS 4.0.0 - 5.4.6, 6.0.0 - 6.1.1

Timeline

  • 2026-05-07: other: Reported date
  • 2026-07-07: patched: Fixed in versions 5.4.7 and 6.1.2
  • 2026-07-07: disclosed: NVD publication date

References