CVE-2026-48901
Joomla! Core - [20260517] - Incorrect Cache Key Construction for InputFilter objects
highEPSS 0.4%
Affected
- bitnami/joomla
4.0.0..* - bitnami/joomla
6.0.0..*
Description
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
bitnamijoomla
4.0.06.0.0Metrics
Show all metrics
Severity
high
65.76
no public PoC known
7.5
Published
2026-05-29 08:44 UTC