Security
Joomla XSS affects generic media output layouts
Administrators running Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 should upgrade to 5.4.9 or 6.1.4 to address a Moderate XSS issue in the generic media output layouts.
The Joomla project’s advisory covers a core issue affecting the generic audio and video output layouts. Its Impact is Moderate, Severity is Moderate and Probability is Low. The exploit type is XSS, identified as CVE-2026-90914.
The problem results from insufficient escaping in the affected layouts. Depending on how the relevant output is handled, attacker-controlled content could be interpreted as script by a browser. Site administrators should treat the update as a maintenance priority for installations using either affected branch.
- Affected Joomla! CMS versions:
4.0.0-5.4.8and6.0.0-6.1.3 - Fixed versions:
5.4.9and6.1.4 - Reported date: 2026-08-13
- Fixed date: 2026-09-25
Aria Akhavan reported the vulnerability. The Joomla project recommends upgrading to the matching fixed release rather than relying on configuration changes, since the advisory identifies the flaw in core output handling.
Published by the Joomla Security Centre.