Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla XSS affects the link toolbar layout

Administrators using Joomla! CMS 4.0.0-5.4.8 or 6.0.0-6.1.3 are affected by an XSS issue in the link toolbar layout; upgrade to 5.4.9 or 6.1.4.

The vulnerability occurs because the link toolbar layout did not properly escape inputs. The Joomla project says this creates an XSS vector, making the layout the affected area in the CMS.

The advisory identifies the issue as CVE-2026-92224. Its risk assessment is:

  • Impact: Moderate
  • Severity: Moderate
  • Probability: Low
  • Exploit type: XSS

The affected product is Joomla! CMS, under the CMS subproject. The issue was reported on 2026-09-10 by Google and Ada Logics, with the fix published on 2026-09-25. Administrators should account for both supported version branches when checking their installations and apply the corresponding maintenance release rather than leaving an affected site on an earlier version.

The advisory was published by the Joomla project as part of its security announcements. Site teams can use the release information to verify that the installed CMS version is outside the affected ranges after updating.

Published by the Joomla Security Centre.