XSS Vulnerability in Joomla! Core Affects Multiple Versions
CVE-2026-92224

5.9MEDIUM

Key Information:

Vendor

Joomla

Vendor
CVE Published:
29 September 2026

What is CVE-2026-92224?

A vulnerability in Joomla! Core allows an attacker to exploit insufficient input validation in the link toolbar layout. This failure to properly escape inputs opens up an avenue for Cross-Site Scripting (XSS) attacks, which can lead to unauthorized actions being executed within the context of a user's browser session. Users of affected Joomla! versions should prioritize patching their installations to mitigate associated risks.

Affected Version(s)

Joomla! CMS 4.0.0-5.4.8

Joomla! CMS 6.0.0-6.1.3

References

CVSS V4

Score:
5.9
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Google and Ada Logics
.