Security
Joomla Framework XSS fixed in cleanAttributes filtering
Joomla! CMS installations running 3.0.0-5.4.5 or 6.0.0-6.1.0 are affected by a Moderate XSS issue in the Framework; upgrade to 5.4.6 or 6.1.1.
The Joomla project says the vulnerability affects the Framework's cleanAttributes filter code, which processes HTML attributes. Insufficient input filtering can allow an XSS vector through this code path. Site administrators should apply the appropriate update, particularly where untrusted or user-supplied HTML is handled.
- Exploit type: XSS
- Severity: Moderate
- Impact: Moderate
- Probability: Moderate
- CVE:
CVE-2026-48905
The affected Joomla! CMS ranges are 3.0.0-5.4.5 and 6.0.0-6.1.0. The corresponding fixed versions are 5.4.6 and 6.1.1. The issue was reported on 2026-05-04 and fixed on 2026-05-26. Jesper den Boer reported the vulnerability.
Administrators should check which supported branch their sites use and upgrade to the matching fixed version. The Joomla! Security Centre lists the JSST as the contact point for this advisory.
Published by the Joomla Security Centre.