CVE-2026-48950: Joomla! Core - [20260704] - XSS in com_templates
Published Jul 7, 2026
·Updated
Lack of escaping leads to an XSS vulnerability in the file management view of comtemplates.
Affected Software
3 affected components
Joomla! Core
Joomla Joomla\!>=4.0.0<5.4.7
Joomla Joomla\!>=6.0.0<6.1.2
Event History
Jul 7, 2026
CVE Published
via MITRE·05:31 PM
Data Sourced
via MITRE·05:31 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48950?
CVE-2026-48950 has a risk rating of 32, indicating a moderate severity level.
2
What is CVE-2026-48950?
CVE-2026-48950 is an XSS vulnerability in the file management view of Joomla! Core's com_templates due to a lack of proper escaping.
3
How do I fix CVE-2026-48950?
To fix CVE-2026-48950, update your Joomla! Core to the latest version that addresses this XSS vulnerability.
4
What systems are affected by CVE-2026-48950?
CVE-2026-48950 affects Joomla! Core installations using the com_templates component.
5
Can CVE-2026-48950 be exploited?
Yes, CVE-2026-48950 can be exploited to execute arbitrary JavaScript in the context of an authenticated user's session.