Security
Joomla InputFilter XSS bypass fixed in 5.4.9 and 6.1.4
Joomla administrators running 1.5.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to fix a Moderate XSS issue in InputFilter.
The Joomla project disclosed the issue as CVE-2026-92232. It affects the CMS and is classified as an XSS exploit with Moderate severity and Low probability.
The vulnerable code processes HTML data URIs through the InputFilter component's cleanAttribute method. Carefully placed whitespace characters can interfere with the filtering logic, allowing unsafe content to pass through and creating a cross-site scripting vector.
- Joomla CMS
1.5.0-5.4.8: upgrade to5.4.9 - Joomla CMS
6.0.0-6.1.3: upgrade to6.1.4
The vulnerability was reported on 2026-08-19 and fixed on 2026-09-25. Administrators should apply the relevant update, particularly on sites that accept or process user-supplied HTML or URI data.
Published by the Joomla Security Centre.