CVE-2026-35221: Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder
Published May 26, 2026
·Updated
Improperly built filter clauses lead to a SQL injection vulnerability in the search query for comfinder.
Affected Software
3 affected components
Joomla Joomla Core (com_finder)
Joomla Joomla\!>=3.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-35221?
The severity of CVE-2026-35221 is medium with a CVSS score of 6.9.
2
How do I fix CVE-2026-35221?
To fix CVE-2026-35221, apply the latest security updates released for Joomla and com_finder.
3
What is the impact of CVE-2026-35221?
CVE-2026-35221 can allow an authenticated attacker to perform blind SQL injection via the com_finder component.
4
Which Joomla versions are affected by CVE-2026-35221?
CVE-2026-35221 affects the Joomla Core component com_finder prior to the patch release on May 27, 2026.
5
What should I do if I cannot patch CVE-2026-35221 immediately?
If immediate patching for CVE-2026-35221 is not possible, restrict user permissions and monitor for abnormal database activity.