OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-90906

HIGH · CVSS 8.3 EPSS 0.22%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Joomla! versions 1.5.0 to 5.4.8 and 6.0.0 to 6.1.3 are vulnerable due to inadequate escaping in the HTMLHelper::link method, which allows for cross-site scripting (XSS) attacks. This vulnerability could enable attackers to inject malicious scripts into web pages, potentially compromising user data and session integrity. Web administrators using affected Joomla! versions should prioritize applying patches to mitigate this security risk.

CVE
CVE-2026-90906
Severity
HIGH
CVSS
8.3
EPSS
0.22%

Original NVD Description

Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to XSS vulnerabilities in the link method of the HTML Helper.

Related CVEs

Other vulnerabilities affecting the same vendor(s)