SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-73372

MEDIUM · CVSS 4.3 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-08-18 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Joomla! versions 5.1.0 to 5.4.7 and 6.0.0 to 6.1.2 are vulnerable due to improper access control checks that allow unauthorized contact information to be injected into schema.org snippets. This could lead to exposure of sensitive data and potential misuse of contact details by attackers. Organizations using these Joomla! versions should prioritize patching to mitigate the risk of data leakage and maintain compliance with data protection standards.

CVE
CVE-2026-73372
Severity
MEDIUM
CVSS
4.3
EPSS
0.21%

Original NVD Description

Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.

Related CVEs

Other vulnerabilities affecting the same vendor(s)