Security
Joomla language overrides expose sites to moderate XSS
Joomla! CMS sites running versions 3.0.0-5.4.5 or 6.0.0-6.1.1 are affected by a Moderate XSS vulnerability in language overrides; administrators should upgrade to 5.4.7 or 6.1.2.
The Joomla project has disclosed a cross-site scripting issue caused by improper validation in the language override feature. The flaw can provide a generic XSS vector, making validation of override-related input the central security concern.
The advisory assigns the issue a severity of Moderate and a probability of Low. It identifies the exploit type as XSS and tracks the vulnerability as CVE-2026-48954.
- Affected installs: Joomla! CMS
3.0.0-5.4.5and6.0.0-6.1.1 - Fixed versions: Joomla! CMS
5.4.7and6.1.2 - Reported date: 2026-05-15
- Fixed date: 2026-07-07
Administrators should apply the appropriate update for their Joomla! CMS branch rather than relying on configuration changes as a workaround. The issue was reported by Morris Baumgarten-Egemole. The Joomla! Security Centre lists the Joomla! Security Strike Team as the contact for this advisory.
Published by the Joomla Security Centre.