MEDIUM
GHSA-fm22-g2q9-j3pw
Joomla! CMS vulnerable to XSS via the input filter
Quick fix
GHSA-fm22-g2q9-j3pw — joomla/filter: upgrade to the fixed version with the command below.
composer require joomla/filter:^4.0.1Details
Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2025-54476[ADVISORY]
- https://github.com/joomla-framework/filter/commit/188dd3fccd6fa0532d105a52736affdf6b166217[WEB]
- https://github.com/joomla-framework/filter/commit/852c7e101c649500d3af58ffb8baf15d7c86d825[WEB]
- https://github.com/joomla-framework/filter/commit/fcde280785f188e93530f7da68102f7dd8f9f723[WEB]
- https://developer.joomla.org/security-centre/1010-20250901-core-inadequate-content-filtering-within-the-checkattribute-filter-code.html[WEB]
- https://github.com/joomla/joomla-cms[PACKAGE]