Security
Joomla fixes XSS in checkAttribute filtering
Joomla CMS sites running 3.0.0-5.4.5 or 6.0.0-6.1.0 should be upgraded to 5.4.6 or 6.1.1 to address a Moderate-severity XSS vulnerability in the Framewok subproject.
The Joomla project says inadequate filtering in the checkAttribute methods can allow cross-site scripting in various components. The advisory identifies the exploit type as XSS and assigns the issue Moderate impact, Moderate severity and Moderate probability.
The affected Joomla! CMS installations are:
3.0.0-5.4.56.0.0-6.1.0
Administrators should select the corresponding maintenance release: 5.4.6 for the first affected branch, or 6.1.1 for the second. These are the fixed versions listed by the project for the issue.
The vulnerability was reported on 2026-04-21 and fixed on 2026-05-26. It is tracked as CVE-2026-48903. The advisory is attributed to the JSST, with the Joomla! Security Centre listed as the contact point for security-related enquiries.
Published by the Joomla Security Centre.