XSS Filter Bypass in Joomla! Core Affects Joomla Versions 1.5 to 6.1
CVE-2026-92231

7.1HIGH

Key Information:

Vendor

Joomla

Vendor
CVE Published:
29 September 2026

What is CVE-2026-92231?

A vulnerability in Joomla! Core allows an XSS filter bypass through an HTML5 entity decode mismatch. The issue arises when the checkAttribute method normalizes an attribute value before validating it against a 'javascript:' scheme regex. This is done without first decoding HTML5 entities, thereby introducing a potential vector for cross-site scripting attacks across Joomla versions 1.5.0 to 6.1.3. Website administrators should take immediate action to update their Joomla installations to mitigate risk.

Affected Version(s)

Joomla! CMS 1.5.0-5.4.8

Joomla! CMS 6.0.0-6.1.3

Joomla! Framework Filter package 1.0.0-3.0.6

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Netanel Stern
.