Joomla! Core - [20260809] - Improper ACL checks when injection schema.org contact data in Joomla 5.1.0-5.4.7 and 6.0.0-6.1.2 - An improper access check injects contact information for unaccessible contact items into schema.org snippets.
Lack of escaping leads to an XSS vulnerability in the update list view of cominstaller.
Lack of escaping leads to an XSS vulnerability in the file management view of comtemplates.