Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla fixes moderate XSS in com_associations

Administrators running affected Joomla! CMS releases should upgrade to a fixed version to address a cross-site scripting issue in the multilingual associations component.

The Joomla project has disclosed an output-escaping flaw in com_associations, the multilingual associations component. The issue creates an XSS vector that could allow injected content to be rendered in an affected installation.

The advisory classifies the impact as Moderate, the severity as Moderate and the probability as Low. It identifies the exploit type as XSS and assigns the issue CVE-2026-25901.

Affected Joomla! CMS installations are those running:

  • 4.0.0-5.4.5
  • 6.0.0-6.1.0

The Joomla project advises upgrading to 5.4.6 or 6.1.1, matching the installation's major version. Administrators should schedule the update promptly and verify that extensions or custom changes involving multilingual associations continue to work afterwards.

The vulnerability was reported by vnth4nhnt from CyStack and Pavel Kohout from Aisle Research. Administrators seeking further information or assistance can contact the JSST through the Joomla Security Centre.

Published by the Joomla Security Centre.