CVE-2026-73336: Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2
Published Aug 18, 2026
·Updated
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
Affected Software
3 affected components
Joomla Joomla! Core>=5.1.0<=5.4.7, >=6.0.0<=6.1.2
Joomla Joomla\!>=5.1.0<5.4.8
Joomla Joomla\!>=6.0.0<=6.1.3
Event History
Aug 18, 2026
CVE Published
via MITRE·04:06 PM
Data Sourced
via MITRE·04:06 PM
DescriptionWeakness
Data Sourced
via NVD·05:17 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
Which Joomla versions are affected?
The affected release ranges are Joomla 5.1.0 through 5.4.7 and Joomla 6.0.0 through 6.1.2. The provided information does not identify any unaffected fixed release.
2
Where should administrators look for exposure?
The issue is an XSS vector in schema.org markup outputs caused by improper escaping flags. Systems using affected versions should review schema.org output paths for values that could contain attacker-controlled content.