Executive brief
Joomla! CMS, a popular website management platform, contains a security flaw in how it handles image displays. An attacker with high-level administrative privileges could use this to inject malicious scripts into the website. If triggered by another user, this could lead to unauthorized actions or data theft within the management console.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in the Joomla! CMS core within the generic image output layout. The issue stems from insufficient output escaping of image-related data. An attacker with high privileges (PR:H) can exploit this over the network to inject malicious scripts. Execution occurs when a victim views the affected layout, potentially allowing for session hijacking or unauthorized administrative actions. The vulnerability affects versions 4.0.0 through 5.4.6 and 6.0.0 through 6.1.1, and is resolved in versions 5.4.7 and 6.1.2.
Affected products
- Joomla! Project Joomla! CMS 4.0.0-5.4.6, 6.0.0-6.1.1
Timeline
- 2026-05-15: other: Reported date
- 2026-07-07: patched: Fixed in versions 5.4.7 and 6.1.2
- 2026-07-07: advisory: Public advisory published