XSS Filter Bypass in Joomla! Core Affects Joomla Versions 1.5 to 6.1
CVE-2026-92231
7.1HIGH
Key Information:
- Vendor
Joomla
- Vendor
- CVE Published:
- 29 September 2026
What is CVE-2026-92231?
A vulnerability in Joomla! Core allows an XSS filter bypass through an HTML5 entity decode mismatch. The issue arises when the checkAttribute method normalizes an attribute value before validating it against a 'javascript:' scheme regex. This is done without first decoding HTML5 entities, thereby introducing a potential vector for cross-site scripting attacks across Joomla versions 1.5.0 to 6.1.3. Website administrators should take immediate action to update their Joomla installations to mitigate risk.
Affected Version(s)
Joomla! CMS 1.5.0-5.4.8
Joomla! CMS 6.0.0-6.1.3
Joomla! Framework Filter package 1.0.0-3.0.6