Security Announcements
This feed provides announcements of resolved security issues in Joomla! software releases.
For more information about the Joomla! Security Strike Team (JSST) and its processes, please review our Security article.
To report potential security issues, please follow the guidelines in the above referenced article. Please note that we are only able to provide support for the Joomla! CMS, Joomla! Framework, and *.joomla.org network of websites.
You can subscribe to notifications from this feed through a RSS reader.
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Low
- Versions: 1.5.0-5.4.8,6.0.0-6.1.3
- Exploit type: XSS
- Reported Date: 2026-08-19
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-92232
Description
Affected Installs
Joomla! CMS versions 1.5.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Low
- Versions: 1.5.0-5.4.8,6.0.0-6.1.3
- Exploit type: XSS
- Reported Date: 2026-08-02
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-92231
Description
Affected Installs
Joomla! CMS versions 1.5.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Moderate
- Probability: Moderate
- Versions: 4.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: Authentication Bypass
- Reported Date: 2026-09-10
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-92227
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Moderate
- Probability: Moderate
- Versions: 4.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: Incorrect Access Control
- Reported Date: 2026-09-10
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-92226
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Low
- Versions: 4.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: XSS
- Reported Date: 2026-09-10
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-92225
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Moderate
- Probability: Moderate
- Versions: 5.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: Incorrect Access Control
- Reported Date: 2026-08-27
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-92223
Description
Affected Installs
Joomla! CMS versions 5.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: High
- Probability: Low
- Versions: 3.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: SSRF
- Reported Date: 2026-08-24
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-92222
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Moderate
- Versions: 4.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: XSS
- Reported Date: 2026-08-24
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-90918
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Low
- Versions: 4.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: XSS
- Reported Date: 2026-09-10
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-92224
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Moderate
- Probability: Moderate
- Versions: 4.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: Incorrect Access Control
- Reported Date: 2026-07-28
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-90917
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Low
- Probability: Low
- Versions: 4.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: Incorrect Access Control
- Reported Date: 2026-07-15
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-90916
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: High
- Probability: Low
- Versions: 4.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: Path Traversal
- Reported Date: 2026-08-13
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-90915
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Low
- Versions: 4.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: XSS
- Reported Date: 2026-08-13
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-90914
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Moderate
- Probability: Moderate
- Versions: 4.0.0-5.4.8,6.0.0-6.1.3
- Exploit type: Incorrect Access Control
- Reported Date: 2026-08-19
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-90913
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Moderate
- Versions: 1.5.0-5.4.8,6.0.0-6.1.3
- Exploit type: Authorization Bypass Through User-Controlled Key
- Reported Date: 2026-08-09
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-90907
Description
Affected Installs
Joomla! CMS versions 1.5.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Low
- Versions: 1.5.0-5.4.8,6.0.0-6.1.3
- Exploit type: XSS
- Reported Date: 2026-08-09
- Fixed Date: 2026-09-25
- CVE Number: CVE-2026-90906
Description
Affected Installs
Joomla! CMS versions 1.5.0-5.4.8, 6.0.0-6.1.3
Solution
Upgrade to version 5.4.9, 6.1.4
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Low
- Probability: Low
- Versions: 1.0.0-5.4.7,6.0.0-6.1.2
- Exploit type: Unrestricted Upload of File with Dangerous Type
- Reported Date: 2026-07-29
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-73373
Description
Affected Installs
Joomla! CMS versions 1.0.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Low
- Probability: Low
- Versions: 5.1.0-5.4.7,6.0.0-6.1.2
- Exploit type: Incorrect Access Control
- Reported Date: 2026-07-31
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-73372
Description
Affected Installs
Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Low
- Severity: Low
- Probability: Low
- Versions: 4.0.0-5.4.7,6.0.0-6.1.2
- Exploit type: Incorrect Access Control
- Reported Date: 2026-07-28
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-73371
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Moderate
- Probability: Moderate
- Versions: 4.0.0-5.4.7,6.0.0-6.1.2
- Exploit type: Authentication Bypass
- Reported Date: 2026-07-25
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-73337
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Low
- Versions: 5.1.0-5.4.7, 6.0.0-6.1.2
- Exploit type: XSS
- Reported Date: 2026-07-21
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-73336
Description
Affected Installs
Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Low
- Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
- Exploit type: Incorrect Access Control
- Reported Date: 2026-07-15
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-72532
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Low
- Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
- Exploit type: Incorrect Access Control
- Reported Date: 2026-07-06
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-72531
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: High
- Severity: Moderate
- Probability: Low
- Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
- Exploit type: Incorrect Access Control
- Reported Date: 2026-07-15
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-71574
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.
- Project: Joomla!
- SubProject: CMS
- Impact: Moderate
- Severity: Moderate
- Probability: Moderate
- Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
- Exploit type: Improper CORS Origin Validation
- Reported Date: 2026-07-09
- Fixed Date: 2026-08-18
- CVE Number: CVE-2026-71573
Description
Affected Installs
Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2
Solution
Upgrade to version 5.4.8, 6.1.3
Contact
The JSST at the Joomla! Security Centre.