Joomla! Core XSS Filter Bypass Vulnerability in Multiple Versions
CVE-2026-92232
7.1HIGH
Key Information:
- Vendor
Joomla
- Vendor
- CVE Published:
- 29 September 2026
What is CVE-2026-92232?
A security issue exists in Joomla! Core versions 1.5.0 through 5.4.8 and 6.0.0 through 6.1.3 that allows for a bypass of the XSS filter through specially crafted HTML data URIs. The cleanAttribute method, designed to remove potentially harmful HTML data URIs, may not fully clean the input if whitespace characters are injected. This can lead to an XSS vector, enabling malicious actors to execute unauthorized scripts within a user's browser session.
Affected Version(s)
Joomla! CMS 1.5.0-5.4.8
Joomla! CMS 6.0.0-6.1.3
Joomla! Framework Filter package 1.0.0-3.0.6