CVE-2026-30895: Joomla! Core - [20260504] - XSS in readmore links
Published May 26, 2026
·Updated
Lack of output escaping leads to a XSS vector in the readmore links for comcontent.
Affected Software
3 affected components
Joomla Joomla Core
Joomla Joomla\!>=3.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:43 PM
Data Sourced
via MITRE·04:43 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-30895?
The severity of CVE-2026-30895 is rated as medium, with a score of 6.9.
2
What is CVE-2026-30895?
CVE-2026-30895 is a vulnerability in Joomla! Core that allows for Cross-Site Scripting (XSS) due to a lack of output escaping in readmore links.
3
How do I fix CVE-2026-30895?
To fix CVE-2026-30895, ensure that you are running the latest version of Joomla! which includes patches for this vulnerability.
4
What is the impact of CVE-2026-30895?
The impact of CVE-2026-30895 could allow attackers to execute arbitrary scripts in the context of the user's session.
5
Is CVE-2026-30895 exploitable?
Yes, CVE-2026-30895 is exploitable, especially if input sanitization and output escaping are not properly implemented.