Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla article title XSS fixed in 5.4.4 and 6.0.4

Administrators running Joomla! CMS 4.0.0-5.4.3 or 6.0.0-6.0.3 should upgrade to 5.4.4 or 6.0.4 to address a Moderate-severity XSS issue.

The Joomla project’s advisory concerns insufficient protection around article title data when it is rendered in several parts of the CMS. An attacker may be able to place script content in a title and have it interpreted in affected output contexts, creating cross-site scripting vectors.

The issue affects Joomla! CMS releases 4.0.0-5.4.3 and 6.0.0-6.0.3. The project identifies the exploit type as XSS, with Impact rated Moderate, Severity rated Moderate and Probability rated Low. The vulnerability is tracked as CVE-2026-21632.

Sites should be updated to Joomla! CMS 5.4.4 or 6.0.4, depending on the installed major version. Administrators may also wish to review article titles and publishing workflows while planning the update, particularly on sites where untrusted users can create or edit content.

The issue was reported on 2026-03-10, and the Joomla project published the fixes on 2026-03-31. The advisory credits peter vanderhulst with reporting the vulnerability.

Published by the Joomla Security Centre.