CVE-2026-92232: Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3
Joomla! Core - [20260916] - Core - XSS filter bypass in InputFilter via whitespace characters in HTML data URIs in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The cleanAttribute method removes HTML data URIs, however injected whitespaces characters could circumvent that cleanup, causing an XSS vector.
Affected Software
Event History
Frequently Asked Questions
Which Joomla versions are affected?
Affected versions are Joomla 1.5.0 through 5.4.8 and Joomla 6.0.0 through 6.1.3.
What must an attacker do to trigger the issue?
The attacker must supply HTML containing a data URI with injected whitespace characters. Those whitespace characters can bypass InputFilter's cleanAttribute cleanup and create an XSS vector.
How can I determine whether my site may be exposed?
Check the installed Joomla version against the affected ranges. Sites that process attacker-controlled HTML through InputFilter are relevant because the bypass occurs in its attribute-cleaning logic.