• About us
    • Joomla Home
    • What is Joomla?
    • Benefits & Features
    • Project & Leadership
    • Trademark & Licensing
    • The Joomla Foundation
    • Support us
    • Contribute
    • Sponsor
    • Partner
    • Shop
    • Downloads
    • Extensions
    • Languages
    • Get a free site
    • Get a domain
    • User Guide
    • Training
    • Certification
    • Site Showcase
    • Announcements
    • Blogs
    • Magazine
    • Community Portal
    • Events
    • User Groups
    • Forum
    • Service Providers Directory
    • Volunteers Portal
    • Vulnerable Extensions List
    • What is Joomla Academy?
    • What is Google Summer of Code (GSoc)
    • Joomla License FAQs
    • Developer Network
    • Developer Manual
    • Security Centre
    • Issue Tracker
    • GitHub
    • API Documentation
    • Joomla! Framework

Joomla! Developer Network™

Download
Launch
  • Home
  • News
  • Project Roadmap
  • CMS
  • Framework
  • Tracker
  • About
  • Security

News

[20260520] - Framework - Inadequate content filtering within the cleanAttributes filter code

Details
Published: 26 May 2026
  • Project: Joomla!
  • SubProject: Framewok
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 3.0.0-5.4.5,6.0.0-6.1.0
  • Exploit type: XSS
  • Reported Date: 2026-05-04
  • Fixed Date: 2026-05-26
  • CVE Number: CVE-2026-48905

Description

Lack of input filtering leads to an XSS vector in the HTML filter code.

Affected Installs

Joomla! CMS versions 3.0.0-5.4.5,6.0.0-6.1.0

Solution

Upgrade to version 5.4.6,6.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Jesper den Boer

[20260519] - Framework - Inadequate content filtering within the checkAttribute filter code

Details
Published: 26 May 2026
  • Project: Joomla!
  • SubProject: Framewok
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 3.0.0-5.4.5,6.0.0-6.1.0
  • Exploit type: XSS
  • Reported Date: 2026-04-21
  • Fixed Date: 2026-05-26
  • CVE Number: CVE-2026-48903

Description

Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.

Affected Installs

Joomla! CMS versions 3.0.0-5.4.5,6.0.0-6.1.0

Solution

Upgrade to version 5.4.6,6.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By:  JSST

[20260518] - Core - Transport encryption downgrade for password and username reset links

Details
Published: 26 May 2026
  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 3.9.0-5.4.5,6.0.0-6.1.0
  • Exploit type: Mixed Content
  • Reported Date: 2026-04-20
  • Fixed Date: 2026-05-26
  • CVE Number: CVE-2026-48902

Description

The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.

Affected Installs

Joomla! CMS versions 3.9.0-5.4.5,6.0.0-6.1.0

Solution

Upgrade to version 5.4.6,6.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By:  ZeroXJacks, Github

[20260517] - Core - Incorrect Cache Key Construction for InputFilter objects

Details
Published: 26 May 2026
  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0-5.4.5,6.0.0-6.1.0
  • Exploit type: Incorrect Cache Key Construction
  • Reported Date: 2025-11-14
  • Fixed Date: 2026-05-26
  • CVE Number: CVE-2026-48901

Description

The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.5,6.0.0-6.1.0

Solution

Upgrade to version 5.4.6,6.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By:  ZeroXJacks, Github

[20260516] - Core - Incorrect Access Control in com_scheduler

Details
Published: 26 May 2026
  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Low
  • Probability: Low
  • Versions: 4.1.0-5.4.5,6.0.0-6.1.0
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-04-29
  • Fixed Date: 2026-05-26
  • CVE Number: CVE-2026-48900

Description

An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.

Affected Installs

Joomla! CMS versions 4.1.0-5.4.5,6.0.0-6.1.0

Solution

Upgrade to version 5.4.6,6.1.1

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Federico Brasili, Linkedin

Page 1 of 61

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  1. You are here:  
  2. Home
  3. News
  4. Security Centre

Joomla! CMS

  • Current Release Joomla! CMS 5 5.x
  • View known Issues
  • Development Status
  • Download Nightly builds

Joomla! Framework

  • Current Release Joomla! Framework Logo 2.x
  • Development Status

Resources

  • Development Strategy
  • Product Strategy
  • Planned Features
  • Security Announcements
  • Report Security Issues
  • Generative AI policy
  • Usage Statistics
  • Statistics API Documentation
  • Joomla! API Documentation
  • Coding Standards Manual
  • JoomlaCode Archive

Mailing Lists

  • Developer Network Newsletter
  • General Extensions Mailing
  • CMS Mailing
  • Framework Mailing
  • Documentation Mailing

  • Joomla! on Facebook
  • Joomla! on X
  • Joomla! on Bluesky
  • Joomla! on Threads
  • Joomla! on YouTube
  • Joomla! on LinkedIn
  • Joomla! on Pinterest
  • Joomla! on Instagram
  • Joomla! on GitHub
  • Home
  • About
  • Community
  • Forum
  • Extensions
  • Services
  • User Guide
  • Developer
  • Shop
  • Accessibility Statement
  • Privacy Policy
  • Cookie Policy
  • Sponsor Joomla! with $5
  • Help Translate
  • Report an Issue
  • Log in
 A Digital Public Good.

© 2005 - 2026 Open Source Matters, Inc. All Rights Reserved.

Rochen
Joomla! Hosting by Rochen
We have detected that you are using an ad blocker. The Joomla! Project relies on revenue from these advertisements so please consider disabling the ad blocker for this domain.