SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-73336

MEDIUM · CVSS 6.4 EPSS 0.19%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Joomla! versions 5.1.0 to 5.4.7 and 6.0.0 to 6.1.2 are vulnerable to cross-site scripting (XSS) due to improper escaping of schema.org markup outputs. This flaw could allow an attacker to inject malicious scripts, potentially compromising user data and session integrity. Web administrators using affected Joomla! versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-73336
Severity
MEDIUM
CVSS
6.4
EPSS
0.19%

Original NVD Description

Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.

Related CVEs

Other vulnerabilities affecting the same vendor(s)