CVE-2026-73336: Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2
Published Aug 18, 2026
·Updated
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
Affected Software
1 affected component
Joomla Joomla! Core>=5.1.0<=5.4.7, >=6.0.0<=6.1.2
Event History
Aug 18, 2026
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Joomla versions are affected?
The affected release ranges are Joomla 5.1.0 through 5.4.7 and Joomla 6.0.0 through 6.1.2. The provided information does not identify any unaffected fixed release.
2
Where should administrators look for exposure?
The issue is an XSS vector in schema.org markup outputs caused by improper escaping flags. Systems using affected versions should review schema.org output paths for values that could contain attacker-controlled content.