PatchSiren cyber security CVE debrief
CVE-2026-48952 Joomla! Project CVE debrief
CVE-2026-48952 is a MEDIUM severity vulnerability with a CVSS score of 5.9, caused by a lack of escaping leading to an XSS vulnerability in the update list view of com_installer. Administrators and users of Joomla should be aware of this vulnerability and take necessary actions to mitigate it. The CVE record was published on 2026-07-07T19:16:53.810Z and has not been modified since then. The vulnerability has a significant impact on the security of Joomla installations.
- Vendor
- Joomla! Project
- Product
- Joomla! CMS
- CVSS
- MEDIUM 5.9
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-07
- Original CVE updated
- 2026-07-09
- Advisory published
- 2026-07-07
- Advisory updated
- 2026-07-09
Who should care
Administrators and users of Joomla, as well as security teams and vulnerability management teams, should be aware of this vulnerability and take necessary actions to mitigate it. The vulnerability affects Joomla's com_installer component and has a MEDIUM severity.
Technical summary
The vulnerability is caused by a lack of escaping in the update list view of com_installer, leading to an XSS vulnerability. The CVSS vector is CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X. The vulnerability has a significant impact on the security of Joomla installations.
Defensive priority
MEDIUM
Recommended defensive actions
- Apply the patch provided by Joomla
- Update com_installer to the latest version
- Monitor for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
Evidence notes
The vulnerability was reported by [email protected] and is related to CWE-79. The evidence is limited, and defenders should verify the affected scope and severity with the vendor. The CVE record was published on 2026-07-07T19:16:53.810Z and has not been modified since then. The vulnerability affects Joomla's com_installer component.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48952 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48952
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48952 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48952
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://developer.joomla.org/security-centre/1060-20260706-core-xss-in-com-installer.html
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.