Security
Joomla InputFilter cache flaw fixed in 5.4.6 and 6.1.1
Joomla installations running 4.0.0-5.4.5 or 6.0.0-6.1.0 are affected by a cache-key issue in InputFilter; administrators should upgrade to 5.4.6 or 6.1.1, as appropriate.
The Joomla project has corrected how InputFilter::getInstance() identifies cached instances. A security-sensitive parameter was not included in the cache key, creating the possibility that an instance could be retrieved under conditions different from those used when it was created.
The advisory assigns the issue CVE-2026-48901. Its exploit type is Incorrect Cache Key Construction, with Impact: Low, Severity: Low and Probability: Low.
- Affected: Joomla CMS
4.0.0-5.4.5and6.0.0-6.1.0 - Fixed: Joomla CMS
5.4.6and6.1.1 - Reported:
2025-11-14 - Fixed:
2026-05-26
The report was submitted by ZeroXJacks via Github. Site owners should check their installed CMS branch and apply the corresponding maintenance release through their usual Joomla update process. Developers maintaining extensions that interact with the input-filtering API should also review their compatibility with the corrected behaviour.
Published by the Joomla Security Centre.