Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla language overrides expose sites to moderate XSS

Joomla! CMS sites running versions 3.0.0-5.4.5 or 6.0.0-6.1.1 are affected by a Moderate XSS vulnerability in language overrides; administrators should upgrade to 5.4.7 or 6.1.2.

The Joomla project has disclosed a cross-site scripting issue caused by improper validation in the language override feature. The flaw can provide a generic XSS vector, making validation of override-related input the central security concern.

The advisory assigns the issue a severity of Moderate and a probability of Low. It identifies the exploit type as XSS and tracks the vulnerability as CVE-2026-48954.

  • Affected installs: Joomla! CMS 3.0.0-5.4.5 and 6.0.0-6.1.1
  • Fixed versions: Joomla! CMS 5.4.7 and 6.1.2
  • Reported date: 2026-05-15
  • Fixed date: 2026-07-07

Administrators should apply the appropriate update for their Joomla! CMS branch rather than relying on configuration changes as a workaround. The issue was reported by Morris Baumgarten-Egemole. The Joomla! Security Centre lists the Joomla! Security Strike Team as the contact for this advisory.

Published by the Joomla Security Centre.