Joomla! Security News
-
[20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Low
- Versions: 1.5.0-5.4.8,6.0.0-6.1.3
- Exploit type: XSS
- Reported Date: 2026-08-19
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-92232
Description
The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circumvent that cleanup, causing an XSS vector.Affected Installs
Joomla! CMS versions 1.5.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
Reported By: arib06 -
[20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Low
- Versions: 1.5.0-5.4.8,6.0.0-6.1.3
- Exploit type: XSS
- Reported Date: 2026-08-02
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-92231
Description
The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector.Affected Installs
Joomla! CMS versions 1.5.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
Reported By: Netanel Stern -
[20260914] - Core - MFA Authentication Bypass through rememberme cookies
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Moderate
- Probability: Moderate
- Versions: 4.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: Authentication Bypass
- Reported Date: 2026-09-10
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-92227
Description
The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability.Affected Installs
Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
Reported By: Google and Ada Logics, Mukul Goyal -
[20260913] - Core - Improper ACL checks for varous webservice edit tasks
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Moderate
- Probability: Moderate
- Versions: 4.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: Incorrect Access Control
- Reported Date: 2026-09-10
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-92226
Description
An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items.Affected Installs
Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
Reported By: Google and Ada Logics -
[20260912] - Core - XSS in module list
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Low
- Versions: 4.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: XSS
- Reported Date: 2026-09-10
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-92225
Description
The module list layout did not properly escape user supplied values, leading to an XSS vector.Affected Installs
Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
Reported By: Google and Ada Logics