CVE-2026-48954: Joomla! Core - [20260708] - XSS through language overrides
Published Jul 7, 2026
·Updated
Improper validation leads to a generic XSS vector in the language override feature.
Affected Software
3 affected components
Joomla Joomla! Core
Joomla Joomla\!>=3.0.0<5.4.7
Joomla Joomla\!>=6.0.0<6.1.2
Event History
Jul 7, 2026
CVE Published
via MITRE·05:29 PM
Data Sourced
via MITRE·05:29 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48954?
CVE-2026-48954 has a risk score of 32, indicating a moderate severity level.
2
How do I fix CVE-2026-48954?
To fix CVE-2026-48954, ensure you are using the latest version of Joomla that addresses this XSS vulnerability in language overrides.
3
What type of vulnerability is CVE-2026-48954?
CVE-2026-48954 is classified as an XSS (Cross-Site Scripting) vulnerability.
4
What causes CVE-2026-48954?
CVE-2026-48954 is caused by improper validation in the language override feature of Joomla.
5
In which Joomla version does CVE-2026-48954 occur?
CVE-2026-48954 affects Joomla! Core prior to the patched version released on July 7, 2026.