OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92225

MEDIUM · CVSS 6.7 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Joomla! versions 4.0.0 to 5.4.8 and 6.0.0 to 6.1.3 are vulnerable due to improper escaping of user-supplied values in the module list layout, which allows for cross-site scripting (XSS) attacks. This vulnerability could enable attackers to execute malicious scripts in the context of a user's session, potentially compromising sensitive information. Organizations using affected Joomla! versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-92225
Severity
MEDIUM
CVSS
6.7
EPSS
0.26%

Original NVD Description

Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector.

Related CVEs

Other vulnerabilities affecting the same vendor(s)