Joomla! Core XSS Filter Bypass Vulnerability in Multiple Versions
CVE-2026-92232

7.1HIGH

Key Information:

Vendor

Joomla

Vendor
CVE Published:
29 September 2026

What is CVE-2026-92232?

A security issue exists in Joomla! Core versions 1.5.0 through 5.4.8 and 6.0.0 through 6.1.3 that allows for a bypass of the XSS filter through specially crafted HTML data URIs. The cleanAttribute method, designed to remove potentially harmful HTML data URIs, may not fully clean the input if whitespace characters are injected. This can lead to an XSS vector, enabling malicious actors to execute unauthorized scripts within a user's browser session.

Affected Version(s)

Joomla! CMS 1.5.0-5.4.8

Joomla! CMS 6.0.0-6.1.3

Joomla! Framework Filter package 1.0.0-3.0.6

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

arib06
.