Security
Joomla fixes XSS in modalreturn layouts
Joomla administrators should upgrade to version 5.4.7 or 6.1.2 to address a Moderate XSS vulnerability in modalreturn layouts, tracked as CVE-2026-48951.
The Joomla project says a lack of escaping creates cross-site scripting vulnerabilities in modalreturn layouts used by various components. The exploit type is XSS, and the assigned Severity is Moderate, with a Low probability.
The advisory’s Versions field lists 4.0.0-5.4.6 and 6.0.0-6.1.1. Its Affected Installs entry specifies Joomla! CMS versions 4.0.0-5.4.5 and 6.0.0-6.1.1. Administrators should check their installed release against both entries and apply the appropriate update: 5.4.7 for the 5.x series or 6.1.2 for the 6.x series.
The issue is identified as CVE-2026-48951. Jorian Woltjer reported it on 2026-05-07, and the Joomla project recorded the fix date as 2026-07-07. The advisory concerns the Joomla! CMS and directs users with questions to the JSST at the Joomla! Security Centre.
Published by the Joomla Security Centre.