Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla fixes XSS in checkAttribute filtering

Joomla CMS sites running 3.0.0-5.4.5 or 6.0.0-6.1.0 should be upgraded to 5.4.6 or 6.1.1 to address a Moderate-severity XSS vulnerability in the Framewok subproject.

The Joomla project says inadequate filtering in the checkAttribute methods can allow cross-site scripting in various components. The advisory identifies the exploit type as XSS and assigns the issue Moderate impact, Moderate severity and Moderate probability.

The affected Joomla! CMS installations are:

  • 3.0.0-5.4.5
  • 6.0.0-6.1.0

Administrators should select the corresponding maintenance release: 5.4.6 for the first affected branch, or 6.1.1 for the second. These are the fixed versions listed by the project for the issue.

The vulnerability was reported on 2026-04-21 and fixed on 2026-05-26. It is tracked as CVE-2026-48903. The advisory is attributed to the JSST, with the Joomla! Security Centre listed as the contact point for security-related enquiries.

Published by the Joomla Security Centre.