CVE-2026-92225

joomla: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CVE-2026-92225)

mediumEPSS 0.3%

Description

Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

bitnamijoomla
4.0.06.0.0

Metrics

6.7
Source: nvd-v3
17.0 %
Elevated — this CVE ranks above at least 10% of all CVEs scored today.
Show all metrics
Severity
medium
no public PoC known
0.3 %
Low — model estimates < 1% exploitation likelihood.
Published
2026-10-07 11:45 UTC
CWE-79

Weakness classes (CWE)

  • CWE-79Base

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

    The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. Initial Analysis2026-10-06 16:35 UTC· nvd@nist.gov
    • CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
    • CPE Configuration: OR *cpe:2.3:a:joomla:joomla!:*:*:*:*:*:*:*:* versions from (including) 4.0.0 up to (excluding) 5.4.8 *cpe:2.3:a:joomla:joomla!:*:*:*:*:*:*:*:* versions from (including) 6.0.0 up to (excluding) 6.1.3
    • Reference Type: Joomla! Project: https://developer.joomla.org/security-centre/1092-20260912-core-xss-in-module-list.html Types: Patch, Vendor Advisory
    • Reference Type: Joomla! Project: https://www.joomla.org/ Types: Product
  2. CVE Modified2026-09-30 16:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
    • SSVC: {"id":"CVE-2026-92225","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
  3. New CVE Received2026-09-29 17:17 UTC· security@joomla.org
    • Description: Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector.
    • CVSS V4.0: AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
    • CWE: CWE-79
    • Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/92xxx/CVE-2026-92225.json">CVE-2026-92225</a>