CVE 6.9 MEDIUM

Joomla! Framework – [20260520] – Inadequate content filtering within the cleanAttributes filter code._CVE-2026-48905

6.9 / 10
MEDIUM
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N

Description

Lack of input filtering leads to an XSS vector in the HTML filter code.

Basic Information

ID CVE-2026-48905
Source Joomla
Published May 26, 2026 at 16:45

Affected Product

Vendor Joomla! Project
Product Joomla! Framework Filter package
Version 1.0.0-3.0.5
Affected Versions Joomla! Project Joomla! Framework Filter package 1.0.0-3.0.5
Joomla! Project Joomla! Framework Filter package 4.0.0-4.0.1

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.