Cross-site scripting in Joomla! - CVE-2026-48905
Published: May 26, 2026
Joomla!
Detailed vulnerability description
The vulnerability allows a remote attacker to execute arbitrary script code in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the cleanAttributes filter code when processing insufficiently filtered HTML content. A remote attacker can supply crafted content to execute arbitrary script code in a victim's browser.