Multiple vulnerabilities in Joomla! (July 08, 2026)
Multiple vulnerabilities have been discovered in Joomla!. Some of them allow an attacker to cause data confidentiality breaches, data integrity breaches, and remote indirect code injection (XSS).
CSIRTS triage
- What
- Multiple vulnerabilities can lead to data confidentiality breaches, data integrity breaches, and remote indirect code injection (XSS).
- Who is affected
- Users of Joomla! installations.
- Urgency
- Remediation is necessary as these vulnerabilities could compromise user data.
- Action
- Users should update to the latest version of Joomla! to mitigate these vulnerabilities.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Joomla!
Get an email when a new Joomla! advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-0847/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-489570.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-489500.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-489530.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-489480.42% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 35% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-489490.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-489560.27% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 19% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-489580.46% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 38% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-489510.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-489540.24% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 15% of all EPSS-scored CVEs.
- Low exploitation riskCVE-2026-489550.34% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 27% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-48957 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48950 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48953 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48948 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48949 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48956 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48958 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48951 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48954 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48955 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48947 | coverage & exploitation status | NVD · CVE.org |
| CVE-2026-48952 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
- high[NEW] [high] Joomla: Multiple vulnerabilitiescert-bund
- highCVE-2026-48958: An improper access check allows unauthorized users to create custom fields via webservices end…nvd
- highCVE-2026-48957: An improper access check allows unauthorized users to access com_privacy datasets.nvd
- mediumCVE-2026-48956: An improper access check allows users to display a list of modules in the frontend.nvd
- mediumCVE-2026-48955: An improper access check allows unauthorized users to access workflow stage and transition inf…nvd
- mediumCVE-2026-48954: Improper validation leads to a generic XSS vector in the language override feature.nvd
- mediumCVE-2026-48953: Lack of escaping leads to an XSS vulnerability in the generic image output layout.nvd
- mediumCVE-2026-48952: Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.nvd
- mediumCVE-2026-48951: Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.nvd
- mediumCVE-2026-48950: Lack of escaping leads to an XSS vulnerability in the file management view of com_templates.nvd
- mediumCVE-2026-48949: Lack of validation leads to an XSS vulnerability in the MFA management views.nvd
- highCVE-2026-48948: An improper access check allows user to download vcard exports of com_contact contacts that ar…nvd
Recent advisories for Joomla!
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- unknownCVE-2026-77998: Joomla Extension - miniorange.com - Unauthenticated Authentication Bypass via SAMLResponse Par…nvd · 2026-08-25
- unknownCVE-2026-77997: Joomla Extension - yootheme.com - Authenticated, privileged information disclosure in YOOtheme…nvd · 2026-08-25
- unknownCVE-2026-77996: Joomla Extension - yootheme.com - Authenticated, privileged stored XSS in YOOtheme Pro 1.0.0-5…nvd · 2026-08-25
- unknownCVE-2026-77995: Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.…nvd · 2026-08-24
- unknownCVE-2026-77994: Joomla Extension - joomlack.fr - Second order SQL injection in Page Builder CK < 3.6.5 - The J…nvd · 2026-08-24
- unknownCVE-2026-77993: Joomla Extension - joomlack.fr - Reflected XSS in Page Builder CK < 3.6.5 - The Joomla extensi…nvd · 2026-08-24
More from CERT-FR Avis de sécurité
- unknownMultiple vulnerabilities in Keycloak (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in Cisco IOS XE (August 25, 2026)2026-08-25
- unknownMultiple vulnerabilities in LibreNMS (August 24, 2026)2026-08-24
- unknownMultiple vulnerabilities in Metabase (August 24, 2026)2026-08-24
- unknownVulnerability in SPIP (August 21, 2026)2026-08-21