Joomla patches multiple XSS and access flaws
CERT-FR advises patching 12 Joomla! vulnerabilities affecting versions before 6.1.2 and 5.4.7, including XSS and broken access control issues.
CERT-FR issued an advisory covering multiple vulnerabilities in the Joomla! content management system, affecting versions 6.x prior to 6.1.2 and versions prior to 5.4.7. The issues include incorrect access control in several core components (com_media, com_contact, com_workflow, com_modules, com_privacy, and com_fields webservice endpoints) as well as multiple cross-site scripting (XSS) flaws in areas such as MFA method management, com_templates, modal return layouts, com_installer, generic image output layouts, and language overrides.
Successful exploitation could allow an attacker to compromise data confidentiality and integrity, bypass security policies, or perform indirect remote code injection via XSS. No evidence of active exploitation is mentioned in the advisory. Twelve CVEs were assigned to these issues, and Joomla has released official patches addressing each vulnerability, referenced through corresponding security center bulletins dated 07 July 2026.
Administrators of affected Joomla! deployments should apply the vendor-provided fixes referenced in the official Joomla! security bulletins as soon as possible to mitigate the risk of data exposure and unauthorized modification.
Mentioned in this report
Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0847
This is the public brief
Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.
Start free