XSS Vulnerability in Joomla! Core Affecting Multiple Versions
CVE-2026-90906

5.9MEDIUM

Key Information:

Vendor

Joomla

Vendor
CVE Published:
29 September 2026

What is CVE-2026-90906?

A Cross-Site Scripting (XSS) vulnerability has been identified in the HTMLHelper::link method of Joomla! Core. This flaw affects multiple versions of Joomla, allowing attackers to inject malicious scripts into the HTML output. The lack of proper escaping means that untrusted input can be executed in users' browsers, potentially compromising user data and session cookies. It is crucial for Joomla users to apply the latest security updates to mitigate this risk, as the vulnerability poses significant security concerns for web applications utilizing the affected frameworks.

Affected Version(s)

Joomla! CMS 1.5.0-5.4.8

Joomla! CMS 6.0.0-6.1.3

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Demyanchuk V.
.