OCTOBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-92224

MEDIUM · CVSS 6.7 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-29 · Last synced 2026-10-07

CyberRota Analysis

AI-Generated

Joomla! versions 4.0.0 to 5.4.8 and 6.0.0 to 6.1.3 are vulnerable due to improper input escaping in the link toolbar layout, which allows for cross-site scripting (XSS) attacks. This vulnerability could enable attackers to inject malicious scripts, potentially compromising user data and site integrity. Web administrators and developers using affected Joomla! versions should prioritize applying patches or updates to mitigate this risk.

CVE
CVE-2026-92224
Severity
MEDIUM
CVSS
6.7
EPSS
0.26%

Original NVD Description

Joomla! Core - [20260911] - Core - XSS in link toolbar layout in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The link toolbar layout did not properly escape inputs, leading to an XSS vector.

Related CVEs

Other vulnerabilities affecting the same vendor(s)