Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Joomla XSS flaw affects 4.x and 6.x installations

Joomla CMS installations running 4.0.0-5.4.5 or 6.0.0-6.1.0 are affected by a Moderate XSS issue in the content history component; administrators should upgrade to 5.4.6 or 6.1.1.

The Joomla project’s advisory describes an output-escaping failure that creates a cross-site scripting vector. The issue is tracked as CVE-2026-30895, with XSS listed as the exploit type.

The project rates the impact as Moderate and the severity as Moderate, while assessing the probability as Low. Although exploitation may require suitable conditions in an affected installation, site owners should treat the update as a routine security maintenance task.

  • Reported date: 2026-04-14
  • Fixed date: 2026-05-26
  • Reported by: peterhulst

The advisory identifies the affected functionality as the content history component. Administrators should confirm which Joomla branch their sites use, apply the corresponding fixed release, and test any extensions or customisations that interact with content history after updating. The Joomla Security Strike Team can be contacted through the Joomla Security Centre for further information.

Published by the Joomla Security Centre.