• About us
    • Joomla Home
    • What is Joomla?
    • Benefits & Features
    • Project & Leadership
    • Trademark & Licensing
    • The Joomla Foundation
    • Support us
    • Contribute
    • Sponsor
    • Partner
    • Shop
    • Downloads
    • Extensions
    • Languages
    • Get a free site
    • Get a domain
    • User Guide
    • Training
    • Certification
    • Site Showcase
    • Announcements
    • Blogs
    • Magazine
    • Community Portal
    • Events
    • User Groups
    • Forum
    • Service Providers Directory
    • Volunteers Portal
    • Vulnerable Extensions List
    • What is Joomla Academy?
    • What is Google Summer of Code (GSoc)
    • Joomla License FAQs
    • Developer Network
    • Developer Manual
    • Security Centre
    • Issue Tracker
    • GitHub
    • API Documentation
    • Joomla! Framework
Joomla! Developer Network™
Download
Launch
  • Home
  • News
  • Project Roadmap
  • CMS
  • Framework
  • Tracker
  • About
  • Security

Security Announcements

This feed provides announcements of resolved security issues in Joomla! software releases.

For more information about the Joomla! Security Strike Team (JSST) and its processes, please review our Security article.

To report potential security issues, please follow the guidelines in the above referenced article. Please note that we are only able to provide support for the Joomla! CMS, Joomla! Framework, and *.joomla.org network of websites.

You can subscribe to notifications from this feed through a RSS reader.

[20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 1.5.0-5.4.8,6.0.0-6.1.3
  • Exploit type: XSS
  • Reported Date: 2026-08-19
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-92232

Description

The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circumvent that cleanup, causing an XSS vector.

Affected Installs

Joomla! CMS versions 1.5.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  arib06

[20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 1.5.0-5.4.8,6.0.0-6.1.3
  • Exploit type: XSS
  • Reported Date: 2026-08-02
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-92231

Description

The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector.

Affected Installs

Joomla! CMS versions 1.5.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Netanel Stern

[20260914] - Core - MFA Authentication Bypass through rememberme cookies

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: Authentication Bypass
  • Reported Date: 2026-09-10
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-92227

Description

The premature issuance of an rememberme cookie leads to a MFA bypass vulnerability.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Google and Ada Logics, Mukul Goyal

[20260913] - Core - Improper ACL checks for varous webservice edit tasks

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-09-10
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-92226

Description

An improper access check allows unauthorized users to perform edit actions on otherwise uneditable items.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Google and Ada Logics

[20260912] - Core - XSS in module list

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: XSS
  • Reported Date: 2026-09-10
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-92225

Description

The module list layout did not properly escape user supplied values, leading to an XSS vector.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Google and Ada Logics

[20260910] - Core - Improper ACL checks for workflow stage changes

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 5.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-08-27
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-92223

Description

An improper access check allows unauthorized users to update the workflow stage of inaccessible contents.

Affected Installs

Joomla! CMS versions 5.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Faceless

[20260909] - Core - SSRF vectors in various core extensions

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: High
  • Probability: Low
  • Versions: 3.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: SSRF
  • Reported Date: 2026-08-24
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-92222

Description

URLs used for serverside requests were improperly validated, leading to SSRF vectors.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Aria Akhavan, Calif.io in collaboration with Anthropic

[20260908] - Core - XSS in HTML Mail Templates

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: XSS
  • Reported Date: 2026-08-24
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90918

Description

The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Joe Grey / GitHub @StressTestor

[20260911] - Core - XSS in link toolbar layout

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: XSS
  • Reported Date: 2026-09-10
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-92224

Description

The link toolbar layout did not properly escape inputs, leading to an XSS vector.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Google and Ada Logics

[20260907] - Core - Improper ACL checks in outputs for tagged items

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-28
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90917

Description

An improper access check allows unauthorized users to view content items from inaccessible categories.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Amin İsayev

[20260906] - Core - Improper ACL checks in content history comparison view

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-15
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90916

Description

An improper access check allows unauthorized users to view inaccessible contents.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Arkadiusz Marta

[20260905] - Core - Arbitrary directory deletion via cache purge action

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: High
  • Probability: Low
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: Path Traversal
  • Reported Date: 2026-08-13
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90915

Description

An improper validation of the cache group name allowed path traverals in the file storage of the caching layer, resulting in arbitrary directory deletions.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Aria Akhavan, Calif.io in collaboration with Anthropic

[20260904] - Core - XSS in the generic media output layouts

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: XSS
  • Reported Date: 2026-08-13
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90914

Description

Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Aria Akhavan

[20260903] - Core - Improper ACL checks for access level webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-08-19
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90913

Description

An improper access check allows unauthorized users to perform mutation actions in access level endpoints.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  sec-reex

[20260902] - Core - Unauthorized user account creation via profile.save controller

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 1.5.0-5.4.8,6.0.0-6.1.3
  • Exploit type: Authorization Bypass Through User-Controlled Key
  • Reported Date: 2026-08-09
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90907

Description

The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user registration.

Affected Installs

Joomla! CMS versions 1.5.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Adithyan P

[20260901] - Core - XSS in HTMLHelper::link method

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 1.5.0-5.4.8,6.0.0-6.1.3
  • Exploit type: XSS
  • Reported Date: 2026-08-09
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90906

Description

Lack of escaping leads to XSS vulnerabilities in the link method of the HTMLHelper.

Affected Installs

Joomla! CMS versions 1.5.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Demyanchuk V.

[20260810] - Core - Unrestricted uploads of SHTML files

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Low
  • Probability: Low
  • Versions: 1.0.0-5.4.7,6.0.0-6.1.2
  • Exploit type: Unrestricted Upload of File with Dangerous Type
  • Reported Date: 2026-07-29
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73373

Description

The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

Affected Installs

Joomla! CMS versions 1.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Valentin Lobstein (Chocapikk)

[20260809] - Core - Improper ACL checks when injection schema.org contact data

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 5.1.0-5.4.7,6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-31
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73372

Description

An improper access check injects contact information for unaccessible contact items into schema.org snippets.

Affected Installs

Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Stefan Wendhausen

[20260808] - Core - Improper ACL checks for batch copy actions

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0-5.4.7,6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-28
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73371

Description

An improper access check allows unauthorized users to perform copy batch operations on uneditable items.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Sabuhi Mammadov

[20260807] - Core - MFA Authentication Bypass

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 4.0.0-5.4.7,6.0.0-6.1.2
  • Exploit type: Authentication Bypass
  • Reported Date: 2026-07-25
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73337

Description

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  bloman, Matej Rada

[20260806] - Core - XSS through schema.org outputs

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 5.1.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: XSS
  • Reported Date: 2026-07-21
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73336

Description

Improper escaping flags lead to an XSS vector in schema.org markup outputs.

Affected Installs

Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Amin İsayev, Geo (GitHub.com/geo-chen)

[20260805] - Core - Improper ACL checks for category webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-15
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-72532

Description

An improper access check allows unauthorized users to create categories for inaccessible components.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Amin İsayev, Geo (GitHub.com/geo-chen)

[20260804] - Core - Improper ACL checks for custom fields webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-06
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-72531

Description

An improper access check allows unauthorized users to create fields for inaccessible components.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  ebadfd

[20260803] - Core - Inconsistent ACL checks for mutating webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-15
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-71574

Description

An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Paul, Sorrachat, tms, Morris Baumgarten-Egemole

[20260802] - Core - Improper CORS origin validation

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Improper CORS Origin Validation
  • Reported Date: 2026-07-09
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-71573

Description

An improper implementation prevented configured CORS origins from being properly validated in CORS requests.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Agamemnon Fakas, caveeroo

Page 1 of 14

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  1. You are here:  
  2. Home
  3. Security Announcements

Joomla! CMS

  • Current Release Joomla! CMS 6 6.x
  • View known Issues
  • Development Status
  • Download Nightly builds

Joomla! Framework

  • Current Release Joomla! Framework Logo 4.x
  • Development Status

Resources

  • Development Strategy
  • Product Strategy
  • Planned Features
  • Security Announcements
  • Report Security Issues
  • Generative AI policy
  • Usage Statistics
  • Statistics API Documentation
  • Joomla! API Documentation
  • Coding Standards Manual
  • JoomlaCode Archive

Mailing Lists

  • Developer Network Newsletter
  • General Extensions Mailing
  • CMS Mailing
  • Framework Mailing
  • Documentation Mailing

  • Joomla! on Facebook
  • Joomla! on X
  • Joomla! on Bluesky
  • Joomla! on Threads
  • Joomla! on YouTube
  • Joomla! on LinkedIn
  • Joomla! on Pinterest
  • Joomla! on Instagram
  • Joomla! on GitHub
  • Home
  • About
  • Community
  • Forum
  • Extensions
  • Services
  • User Guide
  • Developer
  • Shop
  • Accessibility Statement
  • Privacy Policy
  • Cookie Policy
  • Sponsor Joomla! with $5
  • Help Translate
  • Report an Issue
  • Log in
 A Digital Public Good.

© 2005 - 2026 Open Source Matters, Inc. All Rights Reserved.

Rochen
Joomla! Hosting by Rochen
We have detected that you are using an ad blocker. The Joomla! Project relies on revenue from these advertisements so please consider disabling the ad blocker for this domain.