CVE-2026-92231: 
Joomla vulnerability analysis and mitigation

Overview

CVE-2026-92231 is a Cross-Site Scripting (XSS) filter bypass vulnerability in Joomla! CMS and the Joomla! Framework Filter package, caused by an HTML5 entity decode mismatch in the InputFilter class. The checkAttribute method normalized attribute values before testing them against the javascript: scheme regex, but failed to decode HTML5 entities beforehand, allowing attackers to bypass the XSS filter. Affected versions include Joomla! CMS 1.5.0–5.4.8 and 6.0.0–6.1.3, as well as Joomla! Framework Filter package 1.0.0–3.0.6 and 4.0.0–4.1.0. It carries a CVSS v4.0 base score of 7.1 (High) with proof-of-concept exploit maturity (Feedly, Joomla Advisory).

Technical details

The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The vulnerability resides in the checkAttribute method of Joomla!'s InputFilter class, which applies normalization to attribute values prior to checking them against a javascript: scheme regex — but crucially does not decode HTML5 named or numeric character references (entities) before this check. An attacker can craft an attribute value using HTML5 entity encoding (e.g., javascript: or similar) that passes the regex check undetected, yet is interpreted as a javascript: URI by the browser upon rendering. Exploitation requires high privileges (e.g., a backend editor role) and passive user interaction, limiting the attack surface to authenticated scenarios (Feedly, Joomla Advisory).

Impact

Successful exploitation allows an authenticated attacker with elevated privileges to inject and execute arbitrary JavaScript in the context of a victim's browser session, leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim. The vulnerability has high confidentiality and integrity impact within the vulnerable component, with low availability impact. While lateral movement is limited by the requirement for high privileges, a compromised administrator session could result in full site takeover (Feedly).

Exploitability

The CVSS v4.0 exploit maturity is rated as Proof-of-Concept (PoC), indicating that demonstration code exists but no weaponized exploit or active in-the-wild exploitation has been confirmed as of the disclosure date. The Feedly threat intelligence data shows no recorded exploitation events and no public PoC repositories linked at this time. The EPSS score is reported as 0.0, reflecting a currently low probability of exploitation in the wild. There is no indication this CVE has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).

Exploitation steps

  1. Reconnaissance: Identify a target Joomla! CMS instance running versions 1.5.0–5.4.8 or 6.0.0–6.1.3 (or using the vulnerable Framework Filter package). Confirm the version via the Joomla! backend, HTTP response headers, or publicly accessible metadata.
  2. Obtain Privileged Access: Acquire an account with content editing or administrative privileges on the target Joomla! instance (e.g., Editor, Publisher, or Administrator role), as the vulnerability requires high privileges (PR:H).
  3. Craft Malicious Payload: Construct an HTML attribute value that encodes the javascript: scheme using HTML5 entities to bypass the InputFilter regex check. For example, use javascript:alert(1) or similar entity-encoded variants in an href or src attribute within content submitted to the CMS.
  4. Inject via Content Editor: Submit the crafted payload through a content editing interface (e.g., article editor, module, or custom HTML field) that passes input through the vulnerable checkAttribute method.
  5. Trigger Execution: Lure a victim (e.g., another administrator or site visitor) to view the page containing the injected content. The browser decodes the HTML5 entities and executes the JavaScript, enabling session token theft, phishing overlays, or other client-side attacks (Joomla Advisory, Feedly).

Indicators of compromise

  • Logs: Joomla! access logs showing POST requests to content editing endpoints (e.g., /administrator/index.php?option=com_content) containing HTML5 entity-encoded strings in body parameters (e.g., j, j, or similar patterns preceding avascript:).
  • File System: Unexpected modifications to article or module content in the Joomla! database containing obfuscated javascript: URIs within HTML attributes.
  • Network: Outbound requests from victim browsers to attacker-controlled domains following page visits to Joomla! content pages — potentially indicating session token exfiltration or beacon callbacks.
  • Database: Joomla! #__content or #__modules table entries containing HTML attributes with entity-encoded javascript: scheme values (e.g., href="javascript:...").

Mitigation and workarounds

Joomla! has addressed this vulnerability in Joomla! CMS versions 5.4.9 and 6.1.4, and in the Joomla! Framework Filter package versions 3.0.7 and 4.1.1. Administrators should upgrade to these patched releases immediately. As a temporary workaround, restrict content editing privileges to fully trusted users only, and consider deploying a Web Application Firewall (WAF) with rules targeting HTML entity-encoded javascript: scheme patterns in input fields (Joomla Advisory, MySites.guru).

Community reactions

The vulnerability was disclosed via the official Joomla! Security Centre advisory ([20260915]) alongside the release of patched versions 5.4.9 and 6.1.4. Community coverage has appeared on vulnerability tracking platforms including VulDB and CVEFeed, and the MySites.guru blog published a summary of the security release. No notable independent researcher commentary or significant social media discussion has been identified beyond standard CVE aggregation activity (MySites.guru, VulDB).

Additional resources


Source: This report was generated using AI

Related Joomla vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-92227HIGH8.2
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoSep 29, 2026
CVE-2026-92232HIGH7.1
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoSep 29, 2026
CVE-2026-92231HIGH7.1
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoSep 29, 2026
CVE-2026-92226HIGH7
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoSep 29, 2026
CVE-2026-92225MEDIUM5.9
  • Joomla logoJoomla
  • cpe:2.3:a:joomla:joomla\!
NoNoSep 29, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management