Security

Security Announcements

    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.6, 6.0.0-6.1.1
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-05-05
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48958

    Description

    An improper access check allows unauthorized users to create custom fields via webservices endpoints.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.6, 6.0.0-6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Federico Brasili
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.6, 6.0.0-6.1.1
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-06-12
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48957

    Description

    An improper access check allows unauthorized users to access com_privacy datasets.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.6, 6.0.0-6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Himanshu Anand
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.6, 6.0.0-6.1.1
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-05-22
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48956

    Description

    An improper access check allows users to display a list of modules in the frontend.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.6, 6.0.0-6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Warisjeet Singh (sin99xx)
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 6.0.0-6.1.1
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-04-22
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48955

    Description

    An improper access check allows unauthorized users to access workflow stage and transition information.

    Affected Installs

    Joomla! CMS versions 6.0.0-6.1.1

    Solution

    Upgrade to version 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  廖双
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 3.0.0-5.4.6,6.0.0-6.1.1
    • Exploit type: XSS
    • Reported Date: 2026-05-15
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48954

    Description

    Improper validation leads to a generic XSS vector in the language override feature.

    Affected Installs

    Joomla! CMS versions 3.0.0-5.4.5,6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Morris Baumgarten-Egemole
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.6,6.0.0-6.1.1
    • Exploit type: XSS
    • Reported Date: 2026-05-15
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48953

    Description

    Lack of escaping leads to an XSS vulnerability in the generic image output layout.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Pavel Kohout, Aisle Research
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.6,6.0.0-6.1.1
    • Exploit type: XSS
    • Reported Date: 2026-05-21
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48952

    Description

    Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  廖双
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.6,6.0.0-6.1.1
    • Exploit type: XSS
    • Reported Date: 2026-05-07
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48951

    Description

    Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Jorian Woltjer
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.6,6.0.0-6.1.1
    • Exploit type: XSS
    • Reported Date: 2026-05-07
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48950

    Description

    Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Jorian Woltjer
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.2.0-5.4.6,6.0.0-6.1.1
    • Exploit type: XSS
    • Reported Date: 2026-05-07
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48949

    Description

    Lack of validation leads to an XSS vulnerability in the MFA management views.

    Affected Installs

    Joomla! CMS versions 4.2.0-5.4.5,6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Jorian Woltjer
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Low
    • Probability: Low
    • Versions: 3.0.0-5.4.6,6.0.0-6.1.1
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-05-07
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48948

    Description

    An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

    Affected Installs

    Joomla! CMS versions 3.0.0-5.4.5,6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Jorian Woltjer
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Low
    • Probability: Low
    • Versions: 4.1.0-5.4.6,6.0.0-6.1.1
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-05-05
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48947

    Description

    An improper access check allows privileged users to overwrite media files without editing permissions.

    Affected Installs

    Joomla! CMS versions 4.1.0-5.4.6,6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Federico Brasili
    • Project: Joomla!
    • SubProject: Framewok
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Moderate
    • Versions: 3.0.0-5.4.5,6.0.0-6.1.0
    • Exploit type: XSS
    • Reported Date: 2026-05-04
    • Fixed Date: 2026-05-26
    • CVE Number: CVE-2026-48905

    Description

    Lack of input filtering leads to an XSS vector in the HTML filter code.

    Affected Installs

    Joomla! CMS versions 3.0.0-5.4.5,6.0.0-6.1.0

    Solution

    Upgrade to version 5.4.6,6.1.1

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Jesper den Boer
    • Project: Joomla!
    • SubProject: Framewok
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Moderate
    • Versions: 3.0.0-5.4.5,6.0.0-6.1.0
    • Exploit type: XSS
    • Reported Date: 2026-04-21
    • Fixed Date: 2026-05-26
    • CVE Number: CVE-2026-48903

    Description

    Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

    Affected Installs

    Joomla! CMS versions 3.0.0-5.4.5,6.0.0-6.1.0

    Solution

    Upgrade to version 5.4.6,6.1.1

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  JSST
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Low
    • Probability: Low
    • Versions: 3.9.0-5.4.5,6.0.0-6.1.0
    • Exploit type: Mixed Content
    • Reported Date: 2026-04-20
    • Fixed Date: 2026-05-26
    • CVE Number: CVE-2026-48902

    Description

    The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

    Affected Installs

    Joomla! CMS versions 3.9.0-5.4.5,6.0.0-6.1.0

    Solution

    Upgrade to version 5.4.6,6.1.1

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  ZeroXJacks, Github
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Low
    • Probability: Low
    • Versions: 4.0.0-5.4.5,6.0.0-6.1.0
    • Exploit type: Incorrect Cache Key Construction
    • Reported Date: 2025-11-14
    • Fixed Date: 2026-05-26
    • CVE Number: CVE-2026-48901

    Description

    The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.0

    Solution

    Upgrade to version 5.4.6,6.1.1

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  ZeroXJacks, Github
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Low
    • Probability: Low
    • Versions: 4.1.0-5.4.5,6.0.0-6.1.0
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-04-29
    • Fixed Date: 2026-05-26
    • CVE Number: CVE-2026-48900

    Description

    An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

    Affected Installs

    Joomla! CMS versions 4.1.0-5.4.5,6.0.0-6.1.0

    Solution

    Upgrade to version 5.4.6,6.1.1

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Federico Brasili, Linkedin
    • Project: Joomla!
    • SubProject: CMS
    • Impact: High
    • Severity: Moderate
    • Probability: Moderate
    • Versions: 4.0.0-5.4.5,6.0.0-6.1.0
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-04-23
    • Fixed Date: 2026-05-26
    • CVE Number: CVE-2026-48899

    Description

    An improper access check allow unauthorized users to perform actions related to the installation of sampledata.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.0

    Solution

    Upgrade to version 5.4.6,6.1.1

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  廖双, JSST
    • Project: Joomla!
    • SubProject: CMS
    • Impact: High
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.5,6.0.0-6.1.0
    • Exploit type: Privilege Escalation
    • Reported Date: 2026-04-15
    • Fixed Date: 2026-05-26
    • CVE Number: CVE-2026-48904

    Description

    An improper access check allows privelege escalation through the com_users group editing webservice endpoint.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.0

    Solution

    Upgrade to version 5.4.6,6.1.1

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Christos Papakonstantinou, Cantina
    • Project: Joomla!
    • SubProject: CMS
    • Impact: High
    • Severity: High
    • Probability: Low
    • Versions: 4.0.0-5.4.5,6.0.0-6.1.0
    • Exploit type: Privilege Escalation
    • Reported Date: 2026-04-15
    • Fixed Date: 2026-05-26
    • CVE Number: CVE-2026-48898

    Description

    An improper access check allows privlege escalation through the com_users batch task.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.0

    Solution

    Upgrade to version 5.4.6,6.1.1

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Adrian Junge aka vulno, Christos Papakonstantinou, Cantina