CVE-2026-48953
published 2026-07-07CVE-2026-48953: Lack of escaping leads to an XSS vulnerability in the generic image output layout.
PriorityP426medium6.1CVSS 3.1
AVNACLPRNUIRSCCLILAN
EPSS
0.24%
15.9th percentile
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| joomla!_project | joomla!_cms | — | — |
| joomla!_project | joomla!_cms | — | — |
| joomla | joomla_! | >= 4.0.0 < 5.4.7 | 5.4.7 |
| joomla | joomla_! | >= 6.0.0 < 6.1.2 | 6.1.2 |
CVSS provenance
nvdv3.16.1MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
nvdv4.05.9MEDIUMCVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
ghsa_unreviewed·2026-07-07
CVE-2026-48953 [MEDIUM] CWE-79 Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
VulDB
Joomla! Project Joomla! CMS up to 5.4.6/6.1.1 cross site scripting
vuldb·2026-07-07·CVSS 5.9
CVE-2026-48953 [MEDIUM] Joomla! Project Joomla! CMS up to 5.4.6/6.1.1 cross site scripting
A vulnerability labeled as problematic has been found in Joomla! Project Joomla! CMS up to 5.4.6/6.1.1. This issue affects some unknown processing. Executing a manipulation can lead to cross site scripting.
This vulnerability is handled as CVE-2026-48953. The attack can be executed remotely. There is not any exploit available.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-07-07
Published