Junglewise Threat Intelligence

CVE-2026-48952: Joomla! CMS XSS in com_installer update list view

CVE-2026-48952 · Severity: info · CVSS 5.9 · Published 2026-07-07

Technologies: Joomla! Project Joomla! CMS. Vendors: Joomla! Project.

Executive brief

Joomla! CMS, a popular platform for building and managing websites, contains a security flaw in its extension installer component. An attacker with high-level administrative privileges could potentially inject malicious scripts into the update list view. If another administrator views this list, the script could execute, potentially leading to unauthorized actions or data theft within the management console.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in the Joomla! CMS 'com_installer' component. The issue stems from a lack of proper output escaping within the update list view. An attacker with high privileges (PR:H) can exploit this by injecting malicious payloads that execute in the context of another user's browser when they navigate to the affected view. This vulnerability is tracked as CVE-2026-48952 and has been addressed in Joomla! CMS versions 5.4.7 and 6.1.2.

Affected products

  • Joomla! Project Joomla! CMS 4.0.0 - 5.4.6, 6.0.0 - 6.1.1

Timeline

  • 2026-05-21: disclosed: Vulnerability reported to Joomla! Project
  • 2026-07-07: patched: Fixed in versions 5.4.7 and 6.1.2
  • 2026-07-07: advisory

References