Security
Joomla generic image layout exposed to XSS
Administrators running Joomla! CMS 4.0.0-5.4.5 or 6.0.0-6.1.1 should upgrade to 5.4.7 or 6.1.2 to address a Moderate-severity XSS vulnerability in the generic image output layout, tracked as CVE-2026-48953.
The Joomla project published the advisory on 2026-07-07, identifying insufficient escaping in the generic image output layout as the source of the issue. The exploit type is XSS, with the project rating its severity as Moderate and its probability as Low.
The advisory's Versions field lists 4.0.0-5.4.6 and 6.0.0-6.1.1. Its Affected Installs field specifies Joomla! CMS versions 4.0.0-5.4.5 and 6.0.0-6.1.1. Administrators should apply the release corresponding to their major version:
- Joomla! CMS 4 users: upgrade to
5.4.7. - Joomla! CMS 6 users: upgrade to
6.1.2.
Pavel Kohout of Aisle Research reported the vulnerability on 2026-05-15. The Joomla! Security Strike Team lists the fixed date as 2026-07-07 and directs questions to the Joomla! Security Centre.
Published by the Joomla Security Centre.