CVE-2026-40383
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
An improper access control vulnerability in Joomla's com_config webservice endpoints allows unauthorized access to configuration management functions. The vulnerability stems from insufficient authorization checks on webservice API endpoints, enabling authenticated users with elevated privileges to bypass intended access controls. The CVSS 4.0 vector indicates network attack vector with low attack complex [truncated]
## Summary CVE-2026-35222 is a SQL injection vulnerability in the `com_tags` component of Joomla! CMS. The flaw stems from improperly validated `order` clauses, allowing authenticated attackers to manipulate SQL queries. The vulnerability is rated **MEDIUM** severity with a CVSS score of **6.9** (CVSS 4.0 vector: `AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N`). ## Affected Product - **Vendor:** Joomla! (identi [truncated]
A SQL injection vulnerability exists in the Joomla com_finder component due to improperly constructed filter clauses in search queries. The vulnerability requires authenticated access and has been assigned a CVSS 4.0 score of 6.9 (MEDIUM severity). The issue was disclosed by the Joomla Security Centre on May 6, 2026, and subsequently published in the NVD on May 26, 2026. The vulnerability is classified as [truncated]
A Cross-Site Request Forgery (CSRF) vulnerability exists in the admin user activation endpoint of the Joomla com_users component. The flaw stems from missing CSRF token validation, allowing an attacker to trick an authenticated administrator into performing unintended user activation actions via a malicious web page or link. The CVSS 4.0 vector indicates network attack vector with low attack complexity, r [truncated]
A stored cross-site scripting (XSS) vulnerability exists in Joomla's com_content component due to insufficient output escaping in readmore links. The flaw, assigned CVSS 4.0 score 6.9 (Medium), allows an authenticated attacker with high privileges to inject malicious scripts that execute in the context of users clicking affected readmore links. The vulnerability was disclosed by the Joomla Security Strike [truncated]
A stored cross-site scripting (XSS) vulnerability exists in the content history component of Joomla! Core. The flaw stems from insufficient output escaping, allowing an attacker with high privileges to inject malicious scripts that execute in the context of another user's browser session. The vulnerability was disclosed by the Joomla! Security Strike Team and is currently undergoing analysis in the Nation [truncated]
A stored cross-site scripting (XSS) vulnerability exists in the multilingual associations component (com_associations) of Joomla! CMS due to insufficient output escaping. The vulnerability allows authenticated administrative users to inject malicious scripts that execute in the context of other users' browsers. The CVSS 4.0 vector indicates network attack vector with low attack complexity, requiring high [truncated]
CVE-2026-25900 is a cross-site scripting (XSS) vulnerability in Joomla core feed modules, published 2026-05-26. The vulnerability stems from lack of output escaping, allowing crafted input to execute scripts in a victim's browser. CVSS 4.0 vector indicates network attack vector with low attack complexity, requiring high privileges and user interaction, with high confidentiality impact and low integrity/av [truncated]
A lack of output escaping in the pagebreak plugin of Joomla! CMS leads to a cross-site scripting (XSS) vector. This vulnerability, with a CVSS score of 5.9, was publicly disclosed on January 6, 2026, and last modified on September 30, 2026. The affected versions are Joomla! CMS versions from 3.9.0 to 5.4.2 and 6.0.0 to 6.0.2. Defenders and administrators should assess their exposure and take necessary act [truncated]
A lack of input filtering in Joomla leads to an XSS vector in the HTML filter code related to data URLs in img tags. This CVE was published on 2026-01-06T17:15:44.590Z and was last modified on 2026-09-30T23:10:00.237Z. Defenders and administrators of Joomla installations, particularly those using versions 4.0.0 to 5.4.2 and 6.0.0 to 6.0.2, should assess exposure and prioritize patching. The vulnerability [truncated]