CVE-2026-30895

joomla: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CVE-2026-30895)

mediumEPSS 0.2%

Affected

  • bitnami/joomla 3.0.0..*
  • bitnami/joomla 6.0.0..*

Description

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

bitnamijoomla
3.0.06.0.0

Metrics

6.9
Source: nvd-v4
14.4 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.2 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-05-28 08:45 UTC
CWE-79

Weakness classes (CWE)

  • CWE-79Base

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

    cwe.mitre.org →

References & sources