Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla fixes XSS in com_templates file management view

Joomla installations in the affected 4.x, 5.x and 6.x ranges should be upgraded to 5.4.7 or 6.1.2 to address a Moderate XSS vulnerability in com_templates, identified as CVE-2026-48950.

The Joomla project describes the issue as a lack of escaping in the file management view of com_templates. An attacker could use this flaw to inject script content into the affected interface, making it an XSS exploit type. The project rates both the impact and severity as Moderate, with Low probability.

The advisory presents two version ranges relevant to administrators:

  • The listed Versions range is 4.0.0-5.4.6,6.0.0-6.1.1.
  • The Affected Installs range is 4.0.0-5.4.5,6.0.0-6.1.1.

Joomla users should move to the applicable fixed release: 5.4.7 for the 5.x line or 6.1.2 for the 6.x line. Administrators should also review their update procedures and prioritise sites exposing template management to untrusted or lower-privileged users.

The vulnerability was reported on 2026-05-07 and fixed on 2026-07-07. The Joomla Security Strike Team credits Jorian Woltjer for reporting it.

Published by the Joomla Security Centre.