CVE-2026-40383: Joomla! Core - [20260509] - LFI in HTMLView layout parameter
Published May 26, 2026
·Updated
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
Affected Software
3 affected components
Joomla Joomla Core
Joomla Joomla\!>=3.2.1<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-40383?
CVE-2026-40383 has a severity level of high with a CVSS score of 7.5.
2
How do I fix CVE-2026-40383?
To fix CVE-2026-40383, update your Joomla installation to the latest version that addresses this vulnerability.
3
What type of vulnerability is CVE-2026-40383?
CVE-2026-40383 is a local file inclusion vulnerability caused by improper validation of user-supplied input.
4
What impact does CVE-2026-40383 have?
CVE-2026-40383 can allow an attacker to include local files on the server, potentially leading to unauthorized access and data disclosure.
5
Which software versions are affected by CVE-2026-40383?
CVE-2026-40383 affects Joomla! Core and specific versions of Joomla Joomla!.