Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla com_tags affected by authenticated blind SQLi

Joomla administrators using versions 4.0.0-5.4.5 or 6.0.0-6.1.0 should upgrade to 5.4.6 or 6.1.1 to address an authenticated blind SQLi in com_tags, tracked as CVE-2026-352212.

The Joomla project says the vulnerability stems from improperly validated order clauses in com_tags. An authenticated attacker could use crafted input to influence database queries through the component, making this relevant to sites where untrusted users can access the affected functionality.

The advisory classifies the exploit type as SQLi and assigns a Severity of Moderate. Its stated Impact is High, while the Probability is Low. Administrators should treat the upgrade as the appropriate remediation rather than relying on access restrictions alone.

  • Install the applicable fixed release: 5.4.6 for the 5.x branch or 6.1.1 for the 6.x branch.
  • Review update procedures and confirm that production sites are running one of these versions after deployment.

The issue was reported on 2026-03-31 and fixed on 2026-05-26. The Joomla project credits Adrian Junge, also known as vurlo, and Federico Brasili for reporting it.

Published by the Joomla Security Centre.