
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-92231 is a Cross-Site Scripting (XSS) filter bypass vulnerability in Joomla! CMS and the Joomla! Framework Filter package, caused by an HTML5 entity decode mismatch in the InputFilter class. The checkAttribute method normalized attribute values before testing them against the javascript: scheme regex, but failed to decode HTML5 entities beforehand, allowing attackers to bypass the XSS filter. Affected versions include Joomla! CMS 1.5.0–5.4.8 and 6.0.0–6.1.3, as well as Joomla! Framework Filter package 1.0.0–3.0.6 and 4.0.0–4.1.0. It carries a CVSS v4.0 base score of 7.1 (High) with proof-of-concept exploit maturity (Feedly, Joomla Advisory).
The root cause is classified as CWE-79 (Improper Neutralization of Input During Web Page Generation — Cross-Site Scripting). The vulnerability resides in the checkAttribute method of Joomla!'s InputFilter class, which applies normalization to attribute values prior to checking them against a javascript: scheme regex — but crucially does not decode HTML5 named or numeric character references (entities) before this check. An attacker can craft an attribute value using HTML5 entity encoding (e.g., javascript: or similar) that passes the regex check undetected, yet is interpreted as a javascript: URI by the browser upon rendering. Exploitation requires high privileges (e.g., a backend editor role) and passive user interaction, limiting the attack surface to authenticated scenarios (Feedly, Joomla Advisory).
Successful exploitation allows an authenticated attacker with elevated privileges to inject and execute arbitrary JavaScript in the context of a victim's browser session, leading to session hijacking, credential theft, or unauthorized actions performed on behalf of the victim. The vulnerability has high confidentiality and integrity impact within the vulnerable component, with low availability impact. While lateral movement is limited by the requirement for high privileges, a compromised administrator session could result in full site takeover (Feedly).
The CVSS v4.0 exploit maturity is rated as Proof-of-Concept (PoC), indicating that demonstration code exists but no weaponized exploit or active in-the-wild exploitation has been confirmed as of the disclosure date. The Feedly threat intelligence data shows no recorded exploitation events and no public PoC repositories linked at this time. The EPSS score is reported as 0.0, reflecting a currently low probability of exploitation in the wild. There is no indication this CVE has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog (Feedly).
PR:H).javascript: scheme using HTML5 entities to bypass the InputFilter regex check. For example, use javascript:alert(1) or similar entity-encoded variants in an href or src attribute within content submitted to the CMS.checkAttribute method./administrator/index.php?option=com_content) containing HTML5 entity-encoded strings in body parameters (e.g., j, j, or similar patterns preceding avascript:).javascript: URIs within HTML attributes.#__content or #__modules table entries containing HTML attributes with entity-encoded javascript: scheme values (e.g., href="javascript:...").Joomla! has addressed this vulnerability in Joomla! CMS versions 5.4.9 and 6.1.4, and in the Joomla! Framework Filter package versions 3.0.7 and 4.1.1. Administrators should upgrade to these patched releases immediately. As a temporary workaround, restrict content editing privileges to fully trusted users only, and consider deploying a Web Application Firewall (WAF) with rules targeting HTML entity-encoded javascript: scheme patterns in input fields (Joomla Advisory, MySites.guru).
The vulnerability was disclosed via the official Joomla! Security Centre advisory ([20260915]) alongside the release of patched versions 5.4.9 and 6.1.4. Community coverage has appeared on vulnerability tracking platforms including VulDB and CVEFeed, and the MySites.guru blog published a summary of the security release. No notable independent researcher commentary or significant social media discussion has been identified beyond standard CVE aggregation activity (MySites.guru, VulDB).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."