CVE Field Guide
About Us
CVE-2026-21631
PUBLISHED
Joomla! Core - [20260303] - XSS vector in com_associations comparison view
Assigner:
Joomla
Reserved:
01.01.2026
Published:
01.04.2026
Updated:
01.04.2026
Lack of output escaping leads to a XSS vector in the multilingual associations component.
Metrics
CVSS 4.0
CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U
CVSS Score:
5.9
CVSS score
5.9
Exploitability Metrics
Vulnerable System Impact Metrics
Subsequent System Impact Metrics
Attack Vector
Network
Confidentiality
High
Confidentiality
None
Attack Complexity
Low
Integrity
High
Integrity
None
Attack Requirements
None
Availability
Low
Availability
None
Privileges Required
High
User Interaction
Passive
CVSS 4.0
Product Status
Vendor
Joomla! Project
Product
Joomla! CMS
Versions
Default:
unaffected
Version 4.0.0-5.4.3 is affected
Version 6.0.0-6.0.3 is affected
Credits
Shirsendu Mondal & Md Tanzimul Alam Fahim, UNC Pembroke
finder
References
https://developer.joomla.org/security-centre/1029-20260303-core-xss-vector-in-com-associations-comparison-view.html
Problem Types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE
Impacts
CAPEC-18 XSS Targeting Non-Script Elements