CVE-2026-35222: Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags
Published May 26, 2026
·Updated
Improperly validated order clauses lead to a SQL injection vulnerability in comtags.
Affected Software
3 affected components
Joomla Joomla Core
Joomla Joomla\!>=3.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-35222?
CVE-2026-35222 has a medium severity rating of 6.9 according to the CVSS scoring system.
2
How do I fix CVE-2026-35222?
To fix CVE-2026-35222, you should update your Joomla installation to the latest version that addresses the authenticated blind SQL injection vulnerability in com_tags.
3
What type of vulnerability is CVE-2026-35222?
CVE-2026-35222 is an SQL injection vulnerability caused by improperly validated order clauses in Joomla!'s com_tags component.
4
Who is affected by CVE-2026-35222?
CVE-2026-35222 affects users of Joomla! who have the com_tags extension installed and may allow authenticated users to exploit the SQL injection.
5
When was CVE-2026-35222 published?
CVE-2026-35222 was published on May 26, 2026.