CVE-2026-48953: Joomla! Core - [20260707] - XSS in the generic image output layout
Published Jul 7, 2026
·Updated
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Affected Software
3 affected components
Joomla Joomla! Core
Joomla Joomla\!>=4.0.0<5.4.7
Joomla Joomla\!>=6.0.0<6.1.2
Event History
Jul 7, 2026
CVE Published
via MITRE·05:30 PM
Data Sourced
via MITRE·05:30 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48953?
CVE-2026-48953 has a risk rating of 32, indicating it poses a significant security concern.
2
How do I fix CVE-2026-48953?
To fix CVE-2026-48953, update your Joomla! Core to the latest version that addresses the XSS vulnerability.
3
What type of vulnerability is CVE-2026-48953?
CVE-2026-48953 is classified as an XSS (Cross-Site Scripting) vulnerability due to lack of proper escaping.
4
Where is CVE-2026-48953 found?
CVE-2026-48953 is found in the generic image output layout of Joomla! Core.
5
When was CVE-2026-48953 published?
CVE-2026-48953 was published on July 7, 2026.