CVE-2026-25900: Joomla! Core - [20260501] - XSS in feed modules
Published May 26, 2026
·Updated
Lack of output escaping leads to a XSS vector in the feed modules.
Affected Software
3 affected components
Joomla Joomla Core
Joomla Joomla\!>=3.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-25900?
The severity of CVE-2026-25900 is rated as medium with a CVSS score of 6.9.
2
What type of vulnerability is CVE-2026-25900?
CVE-2026-25900 is classified as a cross-site scripting (XSS) vulnerability.
3
How can I mitigate CVE-2026-25900?
To mitigate CVE-2026-25900, ensure that proper output escaping is implemented in feed modules.
4
Who is affected by CVE-2026-25900?
CVE-2026-25900 affects users of the Joomla core software that utilize feed modules.
5
When was CVE-2026-25900 published?
CVE-2026-25900 was published on May 26, 2026.