PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-25901 Joomla! Project CVE debrief

A stored cross-site scripting (XSS) vulnerability exists in the multilingual associations component (com_associations) of Joomla! CMS due to insufficient output escaping. The vulnerability allows authenticated administrative users to inject malicious scripts that execute in the context of other users' browsers. The CVSS 4.0 vector indicates network attack vector with low attack complexity, requiring high privileges and user interaction, with high impact to confidentiality and low impact to integrity and availability. The vulnerability was disclosed by the Joomla! Security Strike Team and is tracked as JSST-2025-0002.

Vendor
Joomla! Project
Product
Joomla! CMS
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-26
Original CVE updated
2026-05-27
Advisory published
2026-05-26
Advisory updated
2026-05-27

Who should care

Joomla! site administrators, security teams managing CMS deployments, and developers maintaining multilingual Joomla! installations should prioritize this patch. Organizations with strict separation of administrative duties may have reduced exposure.

Technical summary

The vulnerability exists in the com_associations component, which manages multilingual content associations in Joomla!. Insufficient output escaping allows script injection that persists and executes when other users view affected associations. The attack requires authenticated administrative privileges, limiting exposure but maintaining significant impact given the elevated access level of typical targets.

Defensive priority

medium

Recommended defensive actions

  • Apply security updates from Joomla! when available per the vendor security advisory
  • Review and restrict administrative access to the multilingual associations component
  • Implement Content Security Policy (CSP) headers to mitigate XSS impact
  • Monitor for suspicious activity in com_associations administrative interface
  • Validate that output encoding is applied to all user-controllable data in multilingual association views

Evidence notes

CVE description confirms XSS via lack of output escaping in multilingual associations component. CVSS 4.0 score of 6.9 (MEDIUM) with vector AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:L/VA:L. Joomla! security advisory reference confirms this is a core XSS vulnerability in com_associations. CWE-79 (Improper Neutralization of Input During Web Page Generation) is the primary weakness. NVD status shows 'Undergoing Analysis' as of last modification.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-25901 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-25901

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-25901 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-25901

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.