Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla com_installer XSS fixed in 5.4.7 and 6.1.2

Joomla administrators running affected CMS releases should upgrade to 5.4.7 or 6.1.2, which fix a Moderate XSS vulnerability in com_installer.

The Joomla project says a lack of escaping exposes the update list view of com_installer to cross-site scripting. The advisory identifies the exploit type as XSS and assigns it Moderate severity, with Low probability and Moderate impact.

Its general version field lists 4.0.0-5.4.6 and 6.0.0-6.1.1. The affected-installs section specifies 4.0.0-5.4.5 and 6.0.0-6.1.1; administrators should follow the stated upgrade path rather than rely on the earlier branch endpoint.

  • CVE: CVE-2026-48952
  • Fixed versions: 5.4.7 and 6.1.2
  • Reported date: 2026-05-21
  • Fixed date: 2026-07-07

The issue was reported by 廖双. Site owners should update promptly, particularly where administrators use the installer’s update list view.

Published by the Joomla Security Centre.