Security
Joomla SSRF flaw affects core extensions
Administrators running affected Joomla! CMS installations should upgrade to 5.4.9 or 6.1.4 to address high-severity SSRF vectors in various core extensions.
The Joomla project assigned this issue CVE-2026-92222. It concerns URLs used for server-side requests that were not validated properly, creating opportunities for server-side request forgery (SSRF).
The advisory identifies the following release ranges:
- The Versions field lists
3.0.0-5.4.8and6.0.0-6.1.3. - The Affected Installs section lists
4.0.0-5.4.8and6.0.0-6.1.3.
For affected installations, the available fixes are 5.4.9 and 6.1.4, corresponding to the applicable Joomla release branch. Site teams should apply the relevant update and review their normal maintenance and testing procedures before deploying it.
The project rates the impact as High, the severity as High and the probability as Low. The exploit type is SSRF. Aria Akhavan reported the vulnerability on 2026-08-24, and the fix was published on 2026-09-25.
Published by the Joomla Security Centre.