CVE-2026-92231
joomla: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CVE-2026-92231)
Description
Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
1.5.06.0.0Metrics
Show all metrics
Weakness classes (CWE)
CWE-79Base
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- Initial Analysis2026-10-06 16:41 UTC· nvd@nist.gov
- CVSS V3.1: AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
- CPE Configuration: OR *cpe:2.3:a:joomla:joomla!:*:*:*:*:*:*:*:* versions from (including) 6.0.0 up to (excluding) 6.1.3 *cpe:2.3:a:joomla:joomla!:*:*:*:*:*:*:*:* versions from (including) 1.5.0 up to (excluding) 5.4.8
- Reference Type: Joomla! Project: https://developer.joomla.org/security-centre/1095-20260915-core-xss-filter-bypass-in-inputfilter-via-html5-entity-decode-mismatch.html Types: Patch, Vendor Advisory
- Reference Type: Joomla! Project: https://www.joomla.org/ Types: Product
- CVE Modified2026-09-30 16:19 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-92231","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalI…
- New CVE Received2026-09-29 17:17 UTC· security@joomla.org
- Description: Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector.
- CVSS V4.0: AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CWE: CWE-79
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/92xxx/CVE-2026-92231.json">CVE-2026-92231</a>