Server-Side Request Forgery Risk in Joomla Core Components
CVE-2026-92222

8.9HIGH

Key Information:

Vendor

Joomla

Vendor
CVE Published:
29 September 2026

What is CVE-2026-92222?

A server-side request forgery (SSRF) vulnerability exists in various core extensions of Joomla! versions 4.0.0 through 5.4.8 and 6.0.0 through 6.1.3. The issue stems from inadequate validation of URLs for server-side requests, potentially allowing attackers to send unauthorized requests from the vulnerable server. This can lead to exposure of sensitive information or interaction with internal services that are not directly accessible from the outside.

Affected Version(s)

Joomla! CMS 4.0.0-5.4.8

Joomla! CMS 6.0.0-6.1.3

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Aria Akhavan
.