Security
Joomla com_installer XSS fixed in 5.4.7 and 6.1.2
Joomla administrators running affected CMS releases should upgrade to 5.4.7 or 6.1.2, which fix a Moderate XSS vulnerability in com_installer.
The Joomla project says a lack of escaping exposes the update list view of com_installer to cross-site scripting. The advisory identifies the exploit type as XSS and assigns it Moderate severity, with Low probability and Moderate impact.
Its general version field lists 4.0.0-5.4.6 and 6.0.0-6.1.1. The affected-installs section specifies 4.0.0-5.4.5 and 6.0.0-6.1.1; administrators should follow the stated upgrade path rather than rely on the earlier branch endpoint.
- CVE:
CVE-2026-48952 - Fixed versions:
5.4.7and6.1.2 - Reported date: 2026-05-21
- Fixed date: 2026-07-07
The issue was reported by 廖双. Site owners should update promptly, particularly where administrators use the installer’s update list view.
Published by the Joomla Security Centre.