Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla fixes high-severity LFI in HTMLView layout parameter

Administrators running Joomla! CMS versions 3.2.1-5.4.5,6.0.0-6.1.0 should upgrade to 5.4.6,6.1.1 to address a High-severity Local File Inclusion vulnerability tracked as CVE-2026-40383.

The Joomla project’s advisory covers an input-validation flaw in the HTMLView layout parameter. Under certain conditions, improperly handled user-supplied input can cause the application to include a local file. The project classifies the impact as High and the probability as Low.

The affected releases are listed as 3.2.1-5.4.5,6.0.0-6.1.0. Site administrators should apply the release corresponding to their supported branch:

  • Upgrade the 5.x series to 5.4.6.
  • Upgrade the 6.x series to 6.1.1.

The issue was reported on 2026-04-15 and fixed on 2026-05-26. Doyensec reported the vulnerability in collaboration with Claude and Anthropic Research. Administrators should review their installed version and schedule the appropriate update promptly, particularly where the affected layout parameter is exposed to untrusted input.

Published by the Joomla Security Centre.