CVE-2026-92231
Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector.
| CWE | CWE-79 |
| Vendor | joomla! project |
| Product | joomla! cms |
| Published | Sep 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for joomla! project joomla! cms
Be the first to know when new unknown vulnerabilities affecting joomla! project joomla! cms are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Joomla! Project / Joomla! CMS
1.5.0-5.4.8 6.0.0-6.1.3
Joomla! Project / Joomla! Framework Filter package
1.0.0-3.0.6 4.0.0-4.1.0
References
Credits
Netanel Stern