CVE-2026-48952: Joomla! Core - [20260706] - XSS in com_installer
Published Jul 7, 2026
·Updated
Lack of escaping leads to an XSS vulnerability in the update list view of cominstaller.
Affected Software
3 affected components
Joomla! Core
Joomla Joomla\!>=4.0.0<5.4.7
Joomla Joomla\!>=6.0.0<6.1.2
Event History
Jul 7, 2026
CVE Published
via MITRE·05:33 PM
Data Sourced
via MITRE·05:33 PM
DescriptionWeakness
Data Sourced
via NVD·07:16 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-48952?
CVE-2026-48952 is rated with a risk score of 32.
2
What type of vulnerability is CVE-2026-48952?
CVE-2026-48952 is an XSS (Cross-Site Scripting) vulnerability.
3
How does CVE-2026-48952 affect Joomla! Core?
CVE-2026-48952 affects Joomla! Core by allowing attackers to execute malicious scripts through a lack of escaping in the update list view of com_installer.
4
How do I fix CVE-2026-48952?
To fix CVE-2026-48952, update Joomla! Core to the latest patched version that addresses the XSS vulnerability.
5
When was CVE-2026-48952 published?
CVE-2026-48952 was published on July 7, 2026.