# Joomla patches multiple XSS and access flaws

Published: 2026-07-08 · Severity: medium · Sectors: technology
Canonical: https://vorant.io/reports/cdefaa74-dac0-567f-aa2b-852558211218/joomla-patches-multiple-xss-and-access-flaws

> CERT-FR advises patching 12 Joomla! vulnerabilities affecting versions before 6.1.2 and 5.4.7, including XSS and broken access control issues.

CERT-FR issued an advisory covering multiple vulnerabilities in the Joomla! content management system, affecting versions 6.x prior to 6.1.2 and versions prior to 5.4.7. The issues include incorrect access control in several core components (com_media, com_contact, com_workflow, com_modules, com_privacy, and com_fields webservice endpoints) as well as multiple cross-site scripting (XSS) flaws in areas such as MFA method management, com_templates, modal return layouts, com_installer, generic image output layouts, and language overrides.

Successful exploitation could allow an attacker to compromise data confidentiality and integrity, bypass security policies, or perform indirect remote code injection via XSS. No evidence of active exploitation is mentioned in the advisory. Twelve CVEs were assigned to these issues, and Joomla has released official patches addressing each vulnerability, referenced through corresponding security center bulletins dated 07 July 2026.

Administrators of affected Joomla! deployments should apply the vendor-provided fixes referenced in the official Joomla! security bulletins as soon as possible to mitigate the risk of data exposure and unauthorized modification.

## Mentioned in this report

- Vulnerabilities: CVE-2026-48947, CVE-2026-48948, CVE-2026-48949, CVE-2026-48950, CVE-2026-48951, CVE-2026-48952, CVE-2026-48953, CVE-2026-48954, CVE-2026-48955, CVE-2026-48956, CVE-2026-48957, CVE-2026-48958

Source reporting: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0847

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/cdefaa74-dac0-567f-aa2b-852558211218/joomla-patches-multiple-xss-and-access-flaws.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
