CVE-2026-25901: Joomla! Core - [20260502] - XSS in com_associations
Published May 26, 2026
·Updated
Lack of output escaping leads to a XSS vector in the multilingual associations component.
Affected Software
3 affected components
Joomla Joomla Core (com_associations)
Joomla Joomla\!>=3.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:44 PM
Data Sourced
via MITRE·04:44 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-25901?
The severity of CVE-2026-25901 is rated as medium with a CVSS score of 6.9.
2
What kind of vulnerability is CVE-2026-25901?
CVE-2026-25901 is a cross-site scripting (XSS) vulnerability in the Joomla! multilingual associations component.
3
How do I fix CVE-2026-25901?
To fix CVE-2026-25901, update your Joomla! installation to the latest version that includes the necessary security patches.
4
What causes CVE-2026-25901?
CVE-2026-25901 is caused by a lack of output escaping in the com_associations component of Joomla!, which allows for XSS attacks.
5
Which software is affected by CVE-2026-25901?
CVE-2026-25901 affects Joomla! and specifically the Joomla! Core component com_associations.