Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla fixes XSS in modalreturn layouts

Joomla administrators should upgrade to version 5.4.7 or 6.1.2 to address a Moderate XSS vulnerability in modalreturn layouts, tracked as CVE-2026-48951.

The Joomla project says a lack of escaping creates cross-site scripting vulnerabilities in modalreturn layouts used by various components. The exploit type is XSS, and the assigned Severity is Moderate, with a Low probability.

The advisory’s Versions field lists 4.0.0-5.4.6 and 6.0.0-6.1.1. Its Affected Installs entry specifies Joomla! CMS versions 4.0.0-5.4.5 and 6.0.0-6.1.1. Administrators should check their installed release against both entries and apply the appropriate update: 5.4.7 for the 5.x series or 6.1.2 for the 6.x series.

The issue is identified as CVE-2026-48951. Jorian Woltjer reported it on 2026-05-07, and the Joomla project recorded the fix date as 2026-07-07. The advisory concerns the Joomla! CMS and directs users with questions to the JSST at the Joomla! Security Centre.

Published by the Joomla Security Centre.