CVE-2026-73372: Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2
Published Aug 18, 2026
·Updated
Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.
Affected Software
2 affected components
Joomla! Core>=5.1.0<=5.4.7
Joomla! Core>=6.0.0<=6.1.2
Event History
Aug 18, 2026
CVE Published
via MITRE·04:05 PM
Data Sourced
via MITRE·04:05 PM
DescriptionWeakness
Frequently Asked Questions
1
Which Joomla! Core release lines should be treated as affected?
Joomla! Core versions 5.1.0 through 5.4.7 and 6.0.0 through 6.1.2 are identified as affected.
2
What information could be exposed?
The issue can cause contact information belonging to contact items that are not accessible to be included in schema.org snippets.