Cross-Site Scripting Vulnerability in Joomla Content Management System
CVE-2026-30895

6.9MEDIUM

Key Information:

Vendor

Joomla

Vendor
CVE Published:
26 May 2026

What is CVE-2026-30895?

This vulnerability arises from a failure to properly escape output in the 'readmore' links of the com_content component, allowing attackers to inject malicious scripts. When users interact with these links, they can inadvertently execute harmful scripts, potentially compromising sensitive information, session tokens, or even site integrity. It is essential for web administrators to apply patches and validate user input to mitigate this risk.

Affected Version(s)

Joomla! CMS 4.0.0-5.4.5

Joomla! CMS 6.0.0-6.1.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

peterhulst
.