CVE-2025-54476: Joomla! Core - [20250901] Inadequate content filtering within the checkAttribute filter code
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class.
Other sources
Improper handling of input could lead to an XSS vector in the checkAttribute method of the input filter framework class.
— MITRE
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-54476?
CVE-2025-54476 has been assessed as a medium severity vulnerability due to its potential for XSS attacks.
How do I fix CVE-2025-54476?
To mitigate CVE-2025-54476, update to the latest version of Joomla! Core that addresses input handling issues.
What causes CVE-2025-54476?
CVE-2025-54476 is caused by improper input handling in the checkAttribute method of Joomla!'s input filter framework.
Who is affected by CVE-2025-54476?
Users running affected versions of Joomla! Core are at risk of exploitation through XSS vectors.
Is CVE-2025-54476 an XSS vulnerability?
Yes, CVE-2025-54476 allows for cross-site scripting (XSS) attacks due to inadequate content filtering.