Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 30 Sep 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Joomla
Joomla joomla! Joomla joomla! Framework Filter Package |
|
| Vendors & Products |
Joomla
Joomla joomla! Joomla joomla! Framework Filter Package |
Wed, 30 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 29 Sep 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - The checkAttribute method normalized an attribute value before testing it against the "javascript:" scheme regex, however without decoding HTML5 entities beforehand, causing an XSS vector. | |
| Title | Joomla! Core - [20260915] - Core - XSS filter bypass in InputFilter via HTML5 entity decode mismatch in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-09-30T16:08:04.934Z
Reserved: 2026-09-15T19:14:31.224Z
Link: CVE-2026-92231
Updated: 2026-09-30T15:26:23.274Z
Status : Awaiting Analysis
Published: 2026-09-29T17:17:14.930
Modified: 2026-09-30T16:19:24.570
Link: CVE-2026-92231
No data.
OpenCVE Enrichment
Updated: 2026-09-30T20:40:49Z