CVE-2026-30894: Joomla! Core - [20260503] - XSS in com_contenthistory
Published May 26, 2026
·Updated
Lack of output escaping leads to a XSS vector in the content history component.
Affected Software
3 affected components
Joomla Joomla Core
Joomla Joomla\!>=3.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:42 PM
Data Sourced
via MITRE·04:42 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30894?
The severity of CVE-2026-30894 is rated as medium with a CVSS score of 6.9.
2
What is CVE-2026-30894?
CVE-2026-30894 is a vulnerability in Joomla's content history component that allows for cross-site scripting (XSS) due to a lack of output escaping.
3
How do I mitigate CVE-2026-30894?
To mitigate CVE-2026-30894, ensure that you apply the latest patches and updates provided by Joomla to address the XSS vulnerability.
4
Who is affected by CVE-2026-30894?
All users of Joomla and its core component 'com_contenthistory' are potentially affected by CVE-2026-30894.
5
Is user interaction required to exploit CVE-2026-30894?
Yes, user interaction is required to exploit CVE-2026-30894 as the XSS vector relies on the manipulation of content history.