Cross-site scripting in Joomla! - CVE-2026-92232
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input during web page generation in the InputFilter cleanAttribute method when handling HTML data URIs containing injected whitespace characters. A remote attacker can inject whitespace characters into an HTML data URI to execute arbitrary script in a victim's browser.
User interaction is required to view content containing the crafted URI.