CVE-2026-48903: Joomla! Framework - [20260519] - Inadequate content filtering within the checkAttribute filter code.
Published May 26, 2026
·Updated
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
Affected Software
3 affected components
Joomla Joomla Framework
Joomla Joomla\!>=3.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.1
Event History
May 26, 2026
CVE Published
via MITRE·04:46 PM
Data Sourced
via MITRE·04:46 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48903?
The severity of CVE-2026-48903 is medium with a score of 6.9 based on the CVSS v3.0 metrics.
2
What type of vulnerability is associated with CVE-2026-48903?
CVE-2026-48903 is associated with Cross-Site Scripting (XSS) vulnerabilities due to inadequate content filtering.
3
How do I fix CVE-2026-48903?
To fix CVE-2026-48903, update your Joomla installation to the latest version where this vulnerability has been addressed.
4
What are the potential impacts of CVE-2026-48903?
The potential impacts of CVE-2026-48903 include unauthorized access to sensitive information and the ability to execute malicious scripts in the user's browser.
5
Is CVE-2026-48903 present in all Joomla versions?
CVE-2026-48903 is primarily associated with specific versions of the Joomla Framework, so it's important to check which version you are using.