• About us
    • Joomla Home
    • What is Joomla?
    • Benefits & Features
    • Project & Leadership
    • Trademark & Licensing
    • The Joomla Foundation
    • Support us
    • Contribute
    • Sponsor
    • Partner
    • Shop
    • Downloads
    • Extensions
    • Languages
    • Get a free site
    • Get a domain
    • User Guide
    • Training
    • Certification
    • Site Showcase
    • Announcements
    • Blogs
    • Magazine
    • Community Portal
    • Events
    • User Groups
    • Forum
    • Service Providers Directory
    • Volunteers Portal
    • Vulnerable Extensions List
    • What is Joomla Academy?
    • What is Google Summer of Code (GSoc)
    • Joomla License FAQs
    • Developer Network
    • Developer Manual
    • Security Centre
    • Issue Tracker
    • GitHub
    • API Documentation
    • Joomla! Framework
Joomla! Developer Network™
Download
Launch
  • Home
  • News
  • Project Roadmap
  • CMS
  • Framework
  • Tracker
  • About
  • Security

Security Announcements

This feed provides announcements of resolved security issues in Joomla! software releases.

For more information about the Joomla! Security Strike Team (JSST) and its processes, please review our Security article.

To report potential security issues, please follow the guidelines in the above referenced article. Please note that we are only able to provide support for the Joomla! CMS, Joomla! Framework, and *.joomla.org network of websites.

You can subscribe to notifications from this feed through a RSS reader.

[20260810] - Core - Unrestricted uploads of SHTML files

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Low
  • Probability: Low
  • Versions: 1.0.0-5.4.7,6.0.0-6.1.2
  • Exploit type: Unrestricted Upload of File with Dangerous Type
  • Reported Date: 2026-07-29
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73373

Description

The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

Affected Installs

Joomla! CMS versions 1.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Valentin Lobstein (Chocapikk)

[20260809] - Core - Improper ACL checks when injection schema.org contact data

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 5.1.0-5.4.7,6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-31
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73372

Description

An improper access check injects contact information for unaccessible contact items into schema.org snippets.

Affected Installs

Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Stefan Wendhausen

[20260808] - Core - Improper ACL checks for batch copy actions

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0-5.4.7,6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-28
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73371

Description

An improper access check allows unauthorized users to perform copy batch operations on uneditable items.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Sabuhi Mammadov

[20260807] - Core - MFA Authentication Bypass

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 4.0.0-5.4.7,6.0.0-6.1.2
  • Exploit type: Authentication Bypass
  • Reported Date: 2026-07-25
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73337

Description

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  bloman, Matej Rada

[20260806] - Core - XSS through schema.org outputs

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 5.1.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: XSS
  • Reported Date: 2026-07-21
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73336

Description

Improper escaping flags lead to an XSS vector in schema.org markup outputs.

Affected Installs

Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Amin İsayev, Geo (GitHub.com/geo-chen)

[20260805] - Core - Improper ACL checks for category webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-15
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-72532

Description

An improper access check allows unauthorized users to create categories for inaccessible components.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Amin İsayev, Geo (GitHub.com/geo-chen)

[20260804] - Core - Improper ACL checks for custom fields webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-06
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-72531

Description

An improper access check allows unauthorized users to create fields for inaccessible components.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  ebadfd

[20260803] - Core - Inconsistent ACL checks for mutating webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-15
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-71574

Description

An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Paul, Sorrachat, tms

[20260802] - Core - Improper CORS origin validation

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Improper CORS Origin Validation
  • Reported Date: 2026-07-09
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-71573

Description

An improper implementation prevented configured CORS origins from being properly validated in CORS requests.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Agamemnon Fakas, caveeroo

[20260801] - Core - Response header injection in download views

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 3.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Response header injection
  • Reported Date: 2026-07-02
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-71572

Description

Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.

Affected Installs

Joomla! CMS versions 3.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  arib06

[20260712] - Core - Incorrect Access Control in com_fields webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.6, 6.0.0-6.1.1
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-05-05
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48958

Description

An improper access check allows unauthorized users to create custom fields via webservices endpoints.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.6, 6.0.0-6.0.0-6.1.1

Solution

Upgrade to version 5.4.7, 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Federico Brasili

[20260711] - Core - Incorrect Access Control in com_privacy webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.6, 6.0.0-6.1.1
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-06-12
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48957

Description

An improper access check allows unauthorized users to access com_privacy datasets.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.6, 6.0.0-6.0.0-6.1.1

Solution

Upgrade to version 5.4.7, 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Himanshu Anand

[20260710] - Core - Incorrect Access Control in com_modules

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.6, 6.0.0-6.1.1
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-05-22
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48956

Description

An improper access check allows users to display a list of modules in the frontend.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.6, 6.0.0-6.0.0-6.1.1

Solution

Upgrade to version 5.4.7, 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Warisjeet Singh (sin99xx)

[20260709] - Core - Incorrect Access Control in com_workflow

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 6.0.0-6.1.1
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-04-22
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48955

Description

An improper access check allows unauthorized users to access workflow stage and transition information.

Affected Installs

Joomla! CMS versions 6.0.0-6.1.1

Solution

Upgrade to version 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  廖双

[20260708] - Core - XSS through language overrides

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 3.0.0-5.4.6,6.0.0-6.1.1
  • Exploit type: XSS
  • Reported Date: 2026-05-15
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48954

Description

Improper validation leads to a generic XSS vector in the language override feature.

Affected Installs

Joomla! CMS versions 3.0.0-5.4.5,6.0.0-6.1.1

Solution

Upgrade to version 5.4.7, 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Morris Baumgarten-Egemole

[20260707] - Core - XSS in the generic image output layout

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.6,6.0.0-6.1.1
  • Exploit type: XSS
  • Reported Date: 2026-05-15
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48953

Description

Lack of escaping leads to an XSS vulnerability in the generic image output layout.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.1

Solution

Upgrade to version 5.4.7, 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Pavel Kohout, Aisle Research

[20260706] - Core - XSS in com_installer

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.6,6.0.0-6.1.1
  • Exploit type: XSS
  • Reported Date: 2026-05-21
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48952

Description

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.1

Solution

Upgrade to version 5.4.7, 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  廖双

[20260705] - Core - XSS in various modalreturn layouts

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.6,6.0.0-6.1.1
  • Exploit type: XSS
  • Reported Date: 2026-05-07
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48951

Description

Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.1

Solution

Upgrade to version 5.4.7, 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Jorian Woltjer

[20260704] - Core - XSS in com_templates

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.6,6.0.0-6.1.1
  • Exploit type: XSS
  • Reported Date: 2026-05-07
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48950

Description

Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.1

Solution

Upgrade to version 5.4.7, 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Jorian Woltjer

[20260703] - Core - XSS in MFA method management

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.2.0-5.4.6,6.0.0-6.1.1
  • Exploit type: XSS
  • Reported Date: 2026-05-07
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48949

Description

Lack of validation leads to an XSS vulnerability in the MFA management views.

Affected Installs

Joomla! CMS versions 4.2.0-5.4.5,6.0.0-6.1.1

Solution

Upgrade to version 5.4.7, 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Jorian Woltjer

[20260702] - Core - Incorrect Access Control in com_contact vcf download

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 3.0.0-5.4.6,6.0.0-6.1.1
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-05-07
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48948

Description

An improper access check allows user to download vcard exports of com_contact contacts that are inaccessible.

Affected Installs

Joomla! CMS versions 3.0.0-5.4.5,6.0.0-6.1.1

Solution

Upgrade to version 5.4.7, 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Jorian Woltjer

[20260701] - Core - Incorrect Access Control in com_media webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Probability: Low
  • Versions: 4.1.0-5.4.6,6.0.0-6.1.1
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-05-05
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48947

Description

An improper access check allows privileged users to overwrite media files without editing permissions.

Affected Installs

Joomla! CMS versions 4.1.0-5.4.6,6.0.0-6.1.1

Solution

Upgrade to version 5.4.7, 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Federico Brasili

[20260520] - Framework - Inadequate content filtering within the cleanAttributes filter code

  • Project: Joomla!
  • SubProject: Framewok
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 3.0.0-5.4.5,6.0.0-6.1.0
  • Exploit type: XSS
  • Reported Date: 2026-05-04
  • Fixed Date: 2026-05-26
  • CVE Number: CVE-2026-48905

Description

Lack of input filtering leads to an XSS vector in the HTML filter code.

Affected Installs

Joomla! CMS versions 3.0.0-5.4.5,6.0.0-6.1.0

Solution

Upgrade to version 5.4.6,6.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Jesper den Boer

[20260519] - Framework - Inadequate content filtering within the checkAttribute filter code

  • Project: Joomla!
  • SubProject: Framewok
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 3.0.0-5.4.5,6.0.0-6.1.0
  • Exploit type: XSS
  • Reported Date: 2026-04-21
  • Fixed Date: 2026-05-26
  • CVE Number: CVE-2026-48903

Description

Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

Affected Installs

Joomla! CMS versions 3.0.0-5.4.5,6.0.0-6.1.0

Solution

Upgrade to version 5.4.6,6.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By:  JSST

[20260518] - Core - Transport encryption downgrade for password and username reset links

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 3.9.0-5.4.5,6.0.0-6.1.0
  • Exploit type: Mixed Content
  • Reported Date: 2026-04-20
  • Fixed Date: 2026-05-26
  • CVE Number: CVE-2026-48902

Description

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Affected Installs

Joomla! CMS versions 3.9.0-5.4.5,6.0.0-6.1.0

Solution

Upgrade to version 5.4.6,6.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By:  ZeroXJacks, Github

Page 1 of 14

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  1. You are here:  
  2. Home
  3. Security Announcements

Joomla! CMS

  • Current Release Joomla! CMS 6 6.x
  • View known Issues
  • Development Status
  • Download Nightly builds

Joomla! Framework

  • Current Release Joomla! Framework Logo 4.x
  • Development Status

Resources

  • Development Strategy
  • Product Strategy
  • Planned Features
  • Security Announcements
  • Report Security Issues
  • Generative AI policy
  • Usage Statistics
  • Statistics API Documentation
  • Joomla! API Documentation
  • Coding Standards Manual
  • JoomlaCode Archive

Mailing Lists

  • Developer Network Newsletter
  • General Extensions Mailing
  • CMS Mailing
  • Framework Mailing
  • Documentation Mailing

  • Joomla! on Facebook
  • Joomla! on X
  • Joomla! on Bluesky
  • Joomla! on Threads
  • Joomla! on YouTube
  • Joomla! on LinkedIn
  • Joomla! on Pinterest
  • Joomla! on Instagram
  • Joomla! on GitHub
  • Home
  • About
  • Community
  • Forum
  • Extensions
  • Services
  • User Guide
  • Developer
  • Shop
  • Accessibility Statement
  • Privacy Policy
  • Cookie Policy
  • Sponsor Joomla! with $5
  • Help Translate
  • Report an Issue
  • Log in
 A Digital Public Good.

© 2005 - 2026 Open Source Matters, Inc. All Rights Reserved.

Rochen
Joomla! Hosting by Rochen
We have detected that you are using an ad blocker. The Joomla! Project relies on revenue from these advertisements so please consider disabling the ad blocker for this domain.