CVE-2026-48949: Joomla! Core - [20260703] - XSS in MFA method management
Published Jul 7, 2026
·Updated
Lack of validation leads to an XSS vulnerability in the MFA management views.
Affected Software
3 affected components
Joomla Joomla! Core
Joomla Joomla\!>=4.2.0<5.4.7
Joomla Joomla\!>=6.0.0<6.1.2
Event History
Jul 7, 2026
CVE Published
via MITRE·05:29 PM
Data Sourced
via MITRE·05:29 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48949?
CVE-2026-48949 has a risk score of 31, indicating a high severity XSS vulnerability.
2
How do I fix CVE-2026-48949?
To fix CVE-2026-48949, ensure that you apply the latest security updates provided by Joomla for the MFA management views.
3
What type of vulnerability is CVE-2026-48949?
CVE-2026-48949 is classified as an XSS (Cross-Site Scripting) vulnerability.
4
Who is affected by CVE-2026-48949?
All Joomla installations using the MFA method management features are potentially affected by CVE-2026-48949.
5
What are the implications of CVE-2026-48949?
Exploitation of CVE-2026-48949 could allow attackers to execute arbitrary scripts in users' browsers, compromising the security of the application.