Security
Joomla module list XSS fixed in CMS updates
Joomla administrators running 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to fix a Moderate XSS vulnerability in the Joomla! CMS module list.
The Joomla project says the module list layout could display user-supplied values without adequate escaping. That creates a cross-site scripting risk, allowing malicious content to be rendered in an administrator-facing area under the right conditions.
The issue is tracked as CVE-2026-92225. Its exploit type is XSS, with the project assigning a Moderate severity and Low probability. Administrators should apply the relevant update rather than relying on configuration changes or user awareness as a mitigation.
Joomla! CMS 4.0.0-5.4.8is fixed in5.4.9.Joomla! CMS 6.0.0-6.1.3is fixed in6.1.4.
Google and Ada Logics reported the vulnerability on 2026-09-10. The Joomla project published the fix on 2026-09-25. Site owners should check their installed branch and schedule the appropriate update promptly, particularly where untrusted users can influence content or access workflows involving the administrator interface.
Published by the Joomla Security Centre.