Security
Joomla fixes XSS flaw in HTML mail templates
Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to address a Moderate XSS vulnerability in HTML mail templates, identified as CVE-2026-90918.
The Joomla project says the mail template feature does not provide an escaping mechanism, allowing cross-site scripting vectors to arise in multiple extensions. The issue affects installations using the listed Joomla! CMS releases and may be relevant to sites that customise or process HTML email templates.
The advisory rates the impact as Moderate, the severity as Moderate, and the probability as Moderate. It identifies the exploit type as XSS. Site owners should schedule the update promptly, test customised mail templates after upgrading, and review any extensions that generate or modify HTML email content.
- Reported date: 2026-08-24
- Fixed date: 2026-09-25
- Reported by: Joe Grey / GitHub @StressTestor
Upgrading is the stated remediation. For supported sites, the relevant fixed releases are 5.4.9 and 6.1.4; administrators should use the release matching their current Joomla branch and confirm that extensions remain compatible.
Published by the Joomla Security Centre.