CVE Field Guide
About Us
CVE-2026-21632
PUBLISHED
Joomla! Core - [20260304] - XSS vectors in various article title outputs
Assigner:
Joomla
Reserved:
01.01.2026
Published:
01.04.2026
Updated:
01.04.2026
Lack of output escaping for article titles leads to XSS vectors in various locations.
Metrics
CVSS 4.0
CVSS Vector:
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U
CVSS Score:
5.9
CVSS score
5.9
Exploitability Metrics
Vulnerable System Impact Metrics
Subsequent System Impact Metrics
Attack Vector
Network
Confidentiality
High
Confidentiality
None
Attack Complexity
Low
Integrity
High
Integrity
None
Attack Requirements
None
Availability
Low
Availability
None
Privileges Required
High
User Interaction
Passive
CVSS 4.0
Product Status
Vendor
Joomla! Project
Product
Joomla! CMS
Versions
Default:
unaffected
Version 4.0.0-5.4.3 is affected
Version 6.0.0-6.0.3 is affected
Credits
peterhulst
finder
References
https://developer.joomla.org/security-centre/1030-20260304-core-xss-vectors-in-various-article-title-outputs.html
Problem Types
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CWE
Impacts
CAPEC-18 XSS Targeting Non-Script Elements