CVE-2025-54476Cross-site Scripting in Joomla Filter

Severity
4.8MEDIUMNVD
EPSS
0.1%
top 84.57%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 30

Description

Improper handling of input could lead to an XSS vector in the checkAttribute method of the input filter framework class.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

Affected Packages2 packages

Packagistjoomla/filter4.0.04.0.1+2
CVEListV5joomla!_project/joomla!_cms3.0.0-3.10.20, 4.0.0-4.4.13, 5.0.0-5.3.3+2

🔴Vulnerability Details

3
CVEList
Joomla! Core - [20250901] Inadequate content filtering within the checkAttribute filter code2025-09-30
OSV
Joomla! CMS vulnerable to XSS via the input filter2025-09-30
GHSA
Joomla! CMS vulnerable to XSS via the input filter2025-09-30