Security

Security Announcements

    • Project: Joomla!
    • SubProject: CMS
    • Impact: High
    • Severity: Low
    • Probability: Low
    • Versions: 1.0.0-5.4.7,6.0.0-6.1.2
    • Exploit type: Unrestricted Upload of File with Dangerous Type
    • Reported Date: 2026-07-29
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-73373

    Description

    The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

    Affected Installs

    Joomla! CMS versions 1.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Valentin Lobstein (Chocapikk)
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Low
    • Probability: Low
    • Versions: 5.1.0-5.4.7,6.0.0-6.1.2
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-07-31
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-73372

    Description

    An improper access check injects contact information for unaccessible contact items into schema.org snippets.

    Affected Installs

    Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Stefan Wendhausen
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Low
    • Probability: Low
    • Versions: 4.0.0-5.4.7,6.0.0-6.1.2
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-07-28
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-73371

    Description

    An improper access check allows unauthorized users to perform copy batch operations on uneditable items.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Sabuhi Mammadov
    • Project: Joomla!
    • SubProject: CMS
    • Impact: High
    • Severity: Moderate
    • Probability: Moderate
    • Versions: 4.0.0-5.4.7,6.0.0-6.1.2
    • Exploit type: Authentication Bypass
    • Reported Date: 2026-07-25
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-73337

    Description

    Insufficient state checks lead to a vector that allows to bypass 2FA checks.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  bloman, Matej Rada
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 5.1.0-5.4.7, 6.0.0-6.1.2
    • Exploit type: XSS
    • Reported Date: 2026-07-21
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-73336

    Description

    Improper escaping flags lead to an XSS vector in schema.org markup outputs.

    Affected Installs

    Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Amin İsayev, Geo (GitHub.com/geo-chen)
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-07-15
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-72532

    Description

    An improper access check allows unauthorized users to create categories for inaccessible components.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Amin İsayev, Geo (GitHub.com/geo-chen)
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-07-06
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-72531

    Description

    An improper access check allows unauthorized users to create fields for inaccessible components.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  ebadfd
    • Project: Joomla!
    • SubProject: CMS
    • Impact: High
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-07-15
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-71574

    Description

    An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Paul, Sorrachat, tms, Morris Baumgarten-Egemole
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Moderate
    • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
    • Exploit type: Improper CORS Origin Validation
    • Reported Date: 2026-07-09
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-71573

    Description

    An improper implementation prevented configured CORS origins from being properly validated in CORS requests.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Agamemnon Fakas, caveeroo
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Low
    • Probability: Low
    • Versions: 3.0.0-5.4.7, 6.0.0-6.1.2
    • Exploit type: Response header injection
    • Reported Date: 2026-07-02
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-71572

    Description

    Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.

    Affected Installs

    Joomla! CMS versions 3.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  arib06
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.6, 6.0.0-6.1.1
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-05-05
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48958

    Description

    An improper access check allows unauthorized users to create custom fields via webservices endpoints.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.6, 6.0.0-6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Federico Brasili
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.6, 6.0.0-6.1.1
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-06-12
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48957

    Description

    An improper access check allows unauthorized users to access com_privacy datasets.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.6, 6.0.0-6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Himanshu Anand
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.6, 6.0.0-6.1.1
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-05-22
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48956

    Description

    An improper access check allows users to display a list of modules in the frontend.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.6, 6.0.0-6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Warisjeet Singh (sin99xx)
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 6.0.0-6.1.1
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-04-22
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48955

    Description

    An improper access check allows unauthorized users to access workflow stage and transition information.

    Affected Installs

    Joomla! CMS versions 6.0.0-6.1.1

    Solution

    Upgrade to version 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  廖双
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 3.0.0-5.4.6,6.0.0-6.1.1
    • Exploit type: XSS
    • Reported Date: 2026-05-15
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48954

    Description

    Improper validation leads to a generic XSS vector in the language override feature.

    Affected Installs

    Joomla! CMS versions 3.0.0-5.4.5,6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Morris Baumgarten-Egemole
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.6,6.0.0-6.1.1
    • Exploit type: XSS
    • Reported Date: 2026-05-15
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48953

    Description

    Lack of escaping leads to an XSS vulnerability in the generic image output layout.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Pavel Kohout, Aisle Research
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.6,6.0.0-6.1.1
    • Exploit type: XSS
    • Reported Date: 2026-05-21
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48952

    Description

    Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  廖双
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.6,6.0.0-6.1.1
    • Exploit type: XSS
    • Reported Date: 2026-05-07
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48951

    Description

    Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Jorian Woltjer
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.6,6.0.0-6.1.1
    • Exploit type: XSS
    • Reported Date: 2026-05-07
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48950

    Description

    Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Jorian Woltjer
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.2.0-5.4.6,6.0.0-6.1.1
    • Exploit type: XSS
    • Reported Date: 2026-05-07
    • Fixed Date: 2026-07-07
    • CVE Number: CVE-2026-48949

    Description

    Lack of validation leads to an XSS vulnerability in the MFA management views.

    Affected Installs

    Joomla! CMS versions 4.2.0-5.4.5,6.0.0-6.1.1

    Solution

    Upgrade to version 5.4.7, 6.1.2

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Jorian Woltjer