CVE-2026-48949
published 2026-07-07CVE-2026-48949: Lack of validation leads to an XSS vulnerability in the MFA management views.
PriorityP428medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.24%
15.9th percentile
Lack of validation leads to an XSS vulnerability in the MFA management views.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| joomla!_project | joomla!_cms | — | — |
| joomla!_project | joomla!_cms | — | — |
| joomla | joomla_! | >= 4.2.0 < 5.4.7 | 5.4.7 |
| joomla | joomla_! | >= 6.0.0 < 6.1.2 | 6.1.2 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv4.05.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Joomla! Project Joomla! CMS MFA Management Views cross site scripting (CNNVD-2026-96395013)
vuldb·2026-07-10·CVSS 6.1
CVE-2026-48949 [MEDIUM] Joomla! Project Joomla! CMS MFA Management Views cross site scripting (CNNVD-2026-96395013)
A vulnerability was found in Joomla! Project Joomla! CMS. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component MFA Management Views. The manipulation results in cross site scripting.
This vulnerability is reported as CVE-2026-48949. The attack can be launched remotely. No exploit exists.
GHSA
Lack of validation leads to an XSS vulnerability in the MFA management views.
ghsa_unreviewed·2026-07-07
CVE-2026-48949 [MEDIUM] CWE-79 Lack of validation leads to an XSS vulnerability in the MFA management views.
Lack of validation leads to an XSS vulnerability in the MFA management views.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-07
Published