Cross-site scripting in Joomla! - CVE-2026-90918
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary script in a victim's browser.
The vulnerability exists due to improper neutralization of input in the mail template feature when generating HTML email content. A remote attacker can inject crafted script content into affected mail templates to execute arbitrary script in a victim's browser.
The issue affects multiple extensions.