Security

Security Announcements

    • Project: Joomla!
    • SubProject: CMS
    • Impact: High
    • Severity: Low
    • Probability: Low
    • Versions: 1.0.0-5.4.7,6.0.0-6.1.2
    • Exploit type: Unrestricted Upload of File with Dangerous Type
    • Reported Date: 2026-07-29
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-73373

    Description

    The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

    Affected Installs

    Joomla! CMS versions 1.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Valentin Lobstein (Chocapikk)
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Low
    • Probability: Low
    • Versions: 5.1.0-5.4.7,6.0.0-6.1.2
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-07-31
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-73372

    Description

    An improper access check injects contact information for unaccessible contact items into schema.org snippets.

    Affected Installs

    Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Stefan Wendhausen
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Low
    • Probability: Low
    • Versions: 4.0.0-5.4.7,6.0.0-6.1.2
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-07-28
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-73371

    Description

    An improper access check allows unauthorized users to perform copy batch operations on uneditable items.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Sabuhi Mammadov
    • Project: Joomla!
    • SubProject: CMS
    • Impact: High
    • Severity: Moderate
    • Probability: Moderate
    • Versions: 4.0.0-5.4.7,6.0.0-6.1.2
    • Exploit type: Authentication Bypass
    • Reported Date: 2026-07-25
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-73337

    Description

    Insufficient state checks lead to a vector that allows to bypass 2FA checks.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  bloman, Matej Rada
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 5.1.0-5.4.7, 6.0.0-6.1.2
    • Exploit type: XSS
    • Reported Date: 2026-07-21
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-73336

    Description

    Improper escaping flags lead to an XSS vector in schema.org markup outputs.

    Affected Installs

    Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Amin İsayev, Geo (GitHub.com/geo-chen)
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-07-15
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-72532

    Description

    An improper access check allows unauthorized users to create categories for inaccessible components.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Amin İsayev, Geo (GitHub.com/geo-chen)
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-07-06
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-72531

    Description

    An improper access check allows unauthorized users to create fields for inaccessible components.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  ebadfd
    • Project: Joomla!
    • SubProject: CMS
    • Impact: High
    • Severity: Moderate
    • Probability: Low
    • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
    • Exploit type: Incorrect Access Control
    • Reported Date: 2026-07-15
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-71574

    Description

    An improper access check allows unauthorized users to perform mutation actions in webservice endpoints, where the same mutation was restricted in the backend UI.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Paul, Sorrachat, tms
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Moderate
    • Severity: Moderate
    • Probability: Moderate
    • Versions: 4.0.0-5.4.7, 6.0.0-6.1.2
    • Exploit type: Improper CORS Origin Validation
    • Reported Date: 2026-07-09
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-71573

    Description

    An improper implementation prevented configured CORS origins from being properly validated in CORS requests.

    Affected Installs

    Joomla! CMS versions 4.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  Agamemnon Fakas, caveeroo
    • Project: Joomla!
    • SubProject: CMS
    • Impact: Low
    • Severity: Low
    • Probability: Low
    • Versions: 3.0.0-5.4.7, 6.0.0-6.1.2
    • Exploit type: Response header injection
    • Reported Date: 2026-07-02
    • Fixed Date: 2026-08-18
    • CVE Number: CVE-2026-71572

    Description

    Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.

    Affected Installs

    Joomla! CMS versions 3.0.0-5.4.7, 6.0.0-6.1.2

    Solution

    Upgrade to version 5.4.8, 6.1.3

    Contact

    The JSST at the Joomla! Security Centre.

    Reported By:  arib06

Upcoming Events

Facebook Page

Joomla! User Group Jeddah

Copyright © 2018-2026 Joomla! User Group Jeddah. All rights reserved. Developed by Moussa Solutions.