Security
Joomla MFA XSS fixed in 5.4.7 and 6.1.2
Joomla! CMS versions 4.2.0-5.4.5 and 6.0.0-6.1.1 are affected by an XSS vulnerability in the MFA management views. The Joomla project rates it Moderate severity with Low probability and identifies it as CVE-2026-48949. Upgrade to 5.4.7 or…
The advisory attributes the problem to a lack of validation in the MFA management views. Insufficient checking of data handled by these views creates the conditions for cross-site scripting. The project lists the exploit type as XSS and does not describe a separate mitigation, making the upgrade the stated remedy.
Administrators should identify sites running an affected release and plan the update using their normal backup and testing procedures. After updating, confirm that MFA administration continues to work as expected and review any locally maintained integrations that interact with this area.
- Installations in the
4.2.0-5.4.5range should move to5.4.7. - Installations in the
6.0.0-6.1.1range should move to6.1.2.
The issue was reported by Jorian Woltjer. Site owners should apply the relevant correction rather than leave vulnerable installations exposed.
Published by the Joomla Security Centre.