OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92231

MEDIUM · CVSS 6.7 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Joomla's InputFilter is vulnerable due to an XSS filter bypass stemming from an HTML5 entity decode mismatch, affecting versions 1.5.0-5.4.8 and 6.0.0-6.1.3. This flaw allows attackers to inject malicious scripts via improperly sanitized attribute values, potentially leading to unauthorized access or data manipulation. Organizations using these Joomla versions should prioritize patching this vulnerability to mitigate the risk of XSS attacks.

CVE
CVE-2026-92231
Severity
MEDIUM
CVSS
6.7
EPSS
0.27%
Java

Original NVD Description

Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector.

Related CVEs

Other vulnerabilities affecting the same vendor(s)