OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-92222

HIGH · CVSS 8 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

Joomla! versions 4.0.0 to 6.1.3 are vulnerable due to improper validation of URLs used for server-side requests, which can lead to Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to manipulate server requests, potentially exposing sensitive internal services and data. Organizations using affected Joomla! versions should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-92222
Severity
HIGH
CVSS
8
EPSS
0.24%

Original NVD Description

Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors.

Related CVEs

Other vulnerabilities affecting the same vendor(s)