Junglewise Threat Intelligence

CVE-2026-48954: Joomla! CMS XSS in language override feature

CVE-2026-48954 · Severity: info · CVSS 5.9 · Published 2026-07-07

Technologies: Joomla! Project Joomla! CMS. Vendors: Joomla! Project.

Executive brief

Joomla! CMS, a popular platform for building and managing websites, contains a security vulnerability in its language override feature. This feature allows administrators to customize text strings used throughout the site. An attacker with high-level administrative privileges could exploit this to inject malicious scripts, potentially leading to unauthorized actions or data theft when other users interact with the affected administrative interface.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in Joomla! CMS versions 3.0.0 through 5.4.6 and 6.0.0 through 6.1.1. The flaw is located in the language override component, where the application fails to properly validate or sanitize user-supplied input before it is stored and rendered. An attacker with high privileges (PR:H) can inject malicious JavaScript into language strings. The exploit requires a victim to interact with the modified language string (UI:P). Successful exploitation could allow for session hijacking or the execution of arbitrary actions in the context of the victim's browser. The issue is resolved in versions 5.4.7 and 6.1.2.

Affected products

  • Joomla! Project Joomla! CMS 3.0.0 - 5.4.6, 6.0.0 - 6.1.1

Timeline

  • 2026-05-15: other: Reported to vendor
  • 2026-07-07: patched: Fixed in versions 5.4.7 and 6.1.2
  • 2026-07-07: disclosed: Public advisory published

References

Related threats