Cross-Site Scripting Vulnerability in Joomla! Core Media Output Layouts
CVE-2026-90914

5.9MEDIUM

Key Information:

Vendor

Joomla

Vendor
CVE Published:
29 September 2026

What is CVE-2026-90914?

A Cross-Site Scripting (XSS) vulnerability exists in the Joomla! Core due to insufficient escaping in the media output layouts. This flaw allows attackers to inject malicious scripts into the audio and video output of the affected versions, potentially compromising the security of the website and its users. Admins and developers using Joomla! versions ranging from 4.0.0 to 6.1.3 are advised to update their installations promptly to mitigate this vulnerability.

Affected Version(s)

Joomla! CMS 4.0.0-5.4.8

Joomla! CMS 6.0.0-6.1.3

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aria Akhavan
.