CVE-2026-48951: Joomla! Core - [20260705] - XSS in various modalreturn layouts
Published Jul 7, 2026
·Updated
Lack of escaping leads to XSS vulnerabilities in modalreturn layouts of various components.
Affected Software
3 affected components
Joomla! Joomla! Core
Joomla Joomla\!>=4.0.0<5.4.7
Joomla Joomla\!>=6.0.0<6.1.2
Event History
Jul 7, 2026
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48951?
CVE-2026-48951 has a risk score of 32, indicating a moderate severity level.
2
What type of vulnerability is identified in CVE-2026-48951?
CVE-2026-48951 is an XSS (Cross-Site Scripting) vulnerability.
3
How do I fix CVE-2026-48951?
To fix CVE-2026-48951, ensure that escaping is properly implemented in all modalreturn layouts within Joomla! components.
4
Which versions of Joomla! are affected by CVE-2026-48951?
CVE-2026-48951 affects various components of the Joomla! Core that utilize modalreturn layouts.
5
What can attackers achieve by exploiting CVE-2026-48951?
By exploiting CVE-2026-48951, attackers can execute arbitrary JavaScript code within the context of the user's browser.