• About us
    • Joomla Home
    • What is Joomla?
    • Benefits & Features
    • Project & Leadership
    • Trademark & Licensing
    • The Joomla Foundation
    • Support us
    • Contribute
    • Sponsor
    • Partner
    • Shop
    • Downloads
    • Extensions
    • Languages
    • Get a free site
    • Get a domain
    • User Guide
    • Training
    • Certification
    • Site Showcase
    • Announcements
    • Blogs
    • Magazine
    • Community Portal
    • Events
    • User Groups
    • Forum
    • Service Providers Directory
    • Volunteers Portal
    • Vulnerable Extensions List
    • What is Joomla Academy?
    • What is Google Summer of Code (GSoc)
    • Joomla License FAQs
    • Developer Network
    • Developer Manual
    • Security Centre
    • Issue Tracker
    • GitHub
    • API Documentation
    • Joomla! Framework
Joomla! Developer Network™
Download
Launch
  • Home
  • News
  • Project Roadmap
  • CMS
  • Framework
  • Tracker
  • About
  • Security

Security Announcements

This feed provides announcements of resolved security issues in Joomla! software releases.

For more information about the Joomla! Security Strike Team (JSST) and its processes, please review our Security article.

To report potential security issues, please follow the guidelines in the above referenced article. Please note that we are only able to provide support for the Joomla! CMS, Joomla! Framework, and *.joomla.org network of websites.

You can subscribe to notifications from this feed through a RSS reader.

[20260910] - Core - Improper ACL checks for workflow stage changes

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 5.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-08-27
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-92223

Description

An improper access check allows unauthorized users to update the workflow stage of inaccessible contents.

Affected Installs

Joomla! CMS versions 5.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Faceless

[20260909] - Core - SSRF vectors in various core extensions

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: High
  • Probability: Low
  • Versions: 3.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: SSRF
  • Reported Date: 2026-08-24
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-92222

Description

URLs used for serverside requests were improperly validated, leading to SSRF vectors.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Aria Akhavan, Calif.io in collaboration with Anthropic

[20260908] - Core - XSS in HTML Mail Templates

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: XSS
  • Reported Date: 2026-08-24
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90918

Description

The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Joe Grey / GitHub @StressTestor

[20260911] - Core - XSS in link toolbar layout

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: XSS
  • Reported Date: 2026-09-10
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-92224

Description

The link toolbar layout did not properly escape inputs, leading to an XSS vector.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Google and Ada Logics

[20260907] - Core - Improper ACL checks in outputs for tagged items

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-28
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90917

Description

An improper access check allows unauthorized users to view content items from inaccessible categories.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Amin İsayev

[20260906] - Core - Improper ACL checks in content history comparison view

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-15
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90916

Description

An improper access check allows unauthorized users to view inaccessible contents.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Arkadiusz Marta

[20260905] - Core - Arbitrary directory deletion via cache purge action

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: High
  • Probability: Low
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: Path Traversal
  • Reported Date: 2026-08-13
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90915

Description

An improper validation of the cache group name allowed path traverals in the file storage of the caching layer, resulting in arbitrary directory deletions.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Aria Akhavan, Calif.io in collaboration with Anthropic

[20260904] - Core - XSS in the generic media output layouts

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: XSS
  • Reported Date: 2026-08-13
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90914

Description

Lack of escaping leads to an XSS vulnerability in the generic audio and video output layouts.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Aria Akhavan

[20260903] - Core - Improper ACL checks for access level webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 4.0.0-5.4.8,6.0.0-6.1.3
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-08-19
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90913

Description

An improper access check allows unauthorized users to perform mutation actions in access level endpoints.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  sec-reex

[20260902] - Core - Unauthorized user account creation via profile.save controller

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 1.5.0-5.4.8,6.0.0-6.1.3
  • Exploit type: Authorization Bypass Through User-Controlled Key
  • Reported Date: 2026-08-09
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90907

Description

The profile.save controller did not check the login state of a user, allowing the creation of guest-level users on sites without active user registration.

Affected Installs

Joomla! CMS versions 1.5.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Adithyan P

[20260901] - Core - XSS in HTMLHelper::link method

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 1.5.0-5.4.8,6.0.0-6.1.3
  • Exploit type: XSS
  • Reported Date: 2026-08-09
  • Fixed Date: 2026-09-25
  • CVE Number: CVE-2026-90906

Description

Lack of escaping leads to XSS vulnerabilities in the link method of the HTMLHelper.

Affected Installs

Joomla! CMS versions 1.5.0-5.4.8, 6.0.0-6.1.3

Solution

Upgrade to version 5.4.9, 6.1.4

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Demyanchuk V.

[20260810] - Core - Unrestricted uploads of SHTML files

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Low
  • Probability: Low
  • Versions: 1.0.0-5.4.7,6.0.0-6.1.2
  • Exploit type: Unrestricted Upload of File with Dangerous Type
  • Reported Date: 2026-07-29
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73373

Description

The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

Affected Installs

Joomla! CMS versions 1.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Valentin Lobstein (Chocapikk)

[20260809] - Core - Improper ACL checks when injection schema.org contact data

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 5.1.0-5.4.7,6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-31
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73372

Description

An improper access check injects contact information for unaccessible contact items into schema.org snippets.

Affected Installs

Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Stefan Wendhausen

[20260808] - Core - Improper ACL checks for batch copy actions

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 4.0.0-5.4.7,6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-28
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73371

Description

An improper access check allows unauthorized users to perform copy batch operations on uneditable items.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Sabuhi Mammadov

[20260807] - Core - MFA Authentication Bypass

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 4.0.0-5.4.7,6.0.0-6.1.2
  • Exploit type: Authentication Bypass
  • Reported Date: 2026-07-25
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73337

Description

Insufficient state checks lead to a vector that allows to bypass 2FA checks.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  bloman, Matej Rada

[20260806] - Core - XSS through schema.org outputs

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 5.1.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: XSS
  • Reported Date: 2026-07-21
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73336

Description

Improper escaping flags lead to an XSS vector in schema.org markup outputs.

Affected Installs

Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Amin İsayev, Geo (GitHub.com/geo-chen)

[20260805] - Core - Improper ACL checks for category webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-15
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-72532

Description

An improper access check allows unauthorized users to create categories for inaccessible components.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Amin İsayev, Geo (GitHub.com/geo-chen)

[20260804] - Core - Improper ACL checks for custom fields webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-06
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-72531

Description

An improper access check allows unauthorized users to create fields for inaccessible components.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  ebadfd

[20260803] - Core - Inconsistent ACL checks for mutating webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-07-15
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-71574

Description

An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Paul, Sorrachat, tms, Morris Baumgarten-Egemole

[20260802] - Core - Improper CORS origin validation

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Moderate
  • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Improper CORS Origin Validation
  • Reported Date: 2026-07-09
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-71573

Description

An improper implementation prevented configured CORS origins from being properly validated in CORS requests.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Agamemnon Fakas, caveeroo

[20260801] - Core - Response header injection in download views

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Low
  • Probability: Low
  • Versions: 3.0.0-5.4.7, 6.0.0-6.1.2
  • Exploit type: Response header injection
  • Reported Date: 2026-07-02
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-71572

Description

Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.

Affected Installs

Joomla! CMS versions 3.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  arib06

[20260712] - Core - Incorrect Access Control in com_fields webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.6, 6.0.0-6.1.1
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-05-05
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48958

Description

An improper access check allows unauthorized users to create custom fields via webservices endpoints.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.6, 6.0.0-6.0.0-6.1.1

Solution

Upgrade to version 5.4.7, 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Federico Brasili

[20260711] - Core - Incorrect Access Control in com_privacy webservice endpoints

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Low
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.6, 6.0.0-6.1.1
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-06-12
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48957

Description

An improper access check allows unauthorized users to access com_privacy datasets.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.6, 6.0.0-6.0.0-6.1.1

Solution

Upgrade to version 5.4.7, 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Himanshu Anand

[20260710] - Core - Incorrect Access Control in com_modules

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 4.0.0-5.4.6, 6.0.0-6.1.1
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-05-22
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48956

Description

An improper access check allows users to display a list of modules in the frontend.

Affected Installs

Joomla! CMS versions 4.0.0-5.4.6, 6.0.0-6.0.0-6.1.1

Solution

Upgrade to version 5.4.7, 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Warisjeet Singh (sin99xx)

[20260709] - Core - Incorrect Access Control in com_workflow

  • Project: Joomla!
  • SubProject: CMS
  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Versions: 6.0.0-6.1.1
  • Exploit type: Incorrect Access Control
  • Reported Date: 2026-04-22
  • Fixed Date: 2026-07-07
  • CVE Number: CVE-2026-48955

Description

An improper access check allows unauthorized users to access workflow stage and transition information.

Affected Installs

Joomla! CMS versions 6.0.0-6.1.1

Solution

Upgrade to version 6.1.2

Contact

The JSST at the Joomla! Security Centre.

Reported By:  廖双

Page 1 of 14

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  1. You are here:  
  2. Home
  3. Security Announcements

Joomla! CMS

  • Current Release Joomla! CMS 6 6.x
  • View known Issues
  • Development Status
  • Download Nightly builds

Joomla! Framework

  • Current Release Joomla! Framework Logo 4.x
  • Development Status

Resources

  • Development Strategy
  • Product Strategy
  • Planned Features
  • Security Announcements
  • Report Security Issues
  • Generative AI policy
  • Usage Statistics
  • Statistics API Documentation
  • Joomla! API Documentation
  • Coding Standards Manual
  • JoomlaCode Archive

Mailing Lists

  • Developer Network Newsletter
  • General Extensions Mailing
  • CMS Mailing
  • Framework Mailing
  • Documentation Mailing

  • Joomla! on Facebook
  • Joomla! on X
  • Joomla! on Bluesky
  • Joomla! on Threads
  • Joomla! on YouTube
  • Joomla! on LinkedIn
  • Joomla! on Pinterest
  • Joomla! on Instagram
  • Joomla! on GitHub
  • Home
  • About
  • Community
  • Forum
  • Extensions
  • Services
  • User Guide
  • Developer
  • Shop
  • Accessibility Statement
  • Privacy Policy
  • Cookie Policy
  • Sponsor Joomla! with $5
  • Help Translate
  • Report an Issue
  • Log in
 A Digital Public Good.

© 2005 - 2026 Open Source Matters, Inc. All Rights Reserved.

Rochen
Joomla! Hosting by Rochen
We have detected that you are using an ad blocker. The Joomla! Project relies on revenue from these advertisements so please consider disabling the ad blocker for this domain.