Joomla! Core - [20260802] - Improper CORS origin validation in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper implementation prevented configured CORS origins from being properly validated in CORS requests.
Joomla! Core - [20260804] - Improper ACL checks for custom fields webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create fields for inaccessible components.
Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.
Joomla! Core - [20260806] - Improper ACL checks for category webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.2 - An improper access check allows unauthorized users to create categories via webservices endpoints.
Lack of escaping leads to an XSS vulnerability in the generic image output layout.
Lack of validation leads to an XSS vulnerability in the MFA management views.
Improper validation leads to a generic XSS vector in the language override feature.
Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of comusers.
Lack of output escaping for article titles leads to XSS vectors in various locations.
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
Lack of output escaping leads to a XSS vector in the pagebreak plugin.