Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla feed modules affected by moderate XSS flaw

Joomla administrators running affected CMS releases should upgrade to 5.4.6 or 6.1.1 to address a moderate XSS vulnerability in feed modules.

The Joomla project says the vulnerability results from a lack of output escaping in the feed modules component. The flaw could provide a cross-site scripting vector, making it relevant to administrators and developers who deploy or maintain affected Joomla! CMS installations.

The advisory rates the issue as Moderate severity, with a Low probability of exploitation. It is tracked as CVE-2026-25900 and is classified as XSS.

  • Affected Joomla! CMS versions: 3.0.0-5.4.5 and 6.0.0-6.1.0
  • Fixed releases: 5.4.6 and 6.1.1
  • Reported date: 2026-03-28
  • Fixed date: 2026-05-26

Mohamed Elabbas and Sun Huang reported the issue. Administrators should apply the appropriate upgrade rather than relying on the vulnerability's Low probability rating, particularly where feed modules are exposed to untrusted or user-controlled content.

Published by the Joomla Security Centre.