Cross-site scripting in Joomla! - CVE-2026-92231
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of HTML5 entities in the InputFilter checkAttribute method when processing attribute values. A remote attacker can submit a crafted attribute value to execute arbitrary script in a victim's browser.