CVE-2026-48905: Joomla! Framework - [20260520] - Inadequate content filtering within the cleanAttributes filter code.
Published May 26, 2026
·Updated
Lack of input filtering leads to an XSS vector in the HTML filter code.
Affected Software
3 affected components
Joomla Joomla Framework
Joomla Joomla\!>=3.0.0<5.4.6
Joomla Joomla\!>=6.0.0<6.1.0
Event History
May 26, 2026
CVE Published
via MITRE·04:45 PM
Data Sourced
via MITRE·04:45 PM
DescriptionWeakness
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48905?
The severity of CVE-2026-48905 is rated as medium with a score of 6.9.
2
What type of vulnerability is CVE-2026-48905?
CVE-2026-48905 is classified as a Cross-Site Scripting (XSS) vulnerability due to inadequate content filtering.
3
How does CVE-2026-48905 affect Joomla?
CVE-2026-48905 affects Joomla users by allowing an XSS vector in the HTML filter code.
4
How do I fix CVE-2026-48905?
To fix CVE-2026-48905, update your Joomla installation to the latest version that addresses the inadequate content filtering issue.
5
When was CVE-2026-48905 published?
CVE-2026-48905 was published on May 26, 2026.