Stored XSS via schema.org markup output in Joomla! core 5.1.0–5.4.7 and 6.0.0–6.1.2
AI analysis
Joomla! core contains a cross-site scripting flaw (CWE-79) in which improperly set escaping flags allow malicious markup to pass unescaped into the schema.org structured-data output that the CMS renders on pages. An attacker who already holds elevated privileges on the site (the CVSS 4.0 vector requires high privileges, PR:H) can plant content or fields that the schema.org emitter then outputs without escaping, so attacker-supplied JavaScript executes in the browsers of anyone loading the affected pages, with no additional user interaction required. The practical gain is script execution in victims' session contexts, though the 5.1 medium CVSS 4.0 score indicates low-impact confidentiality and integrity effects rather than full system compromise. All sites running Joomla! 5.1.0 through 5.4.7 or 6.0.0 through 6.1.2 are affected. No public proof-of-concept is known, the issue is not in the CISA KEV catalog, and EPSS estimates only about a 0.2% chance of exploitation in the next 30 days, so no exploitation is currently known.
What to do: Upgrade Joomla! core to a release above the affected ranges — any 5.4.x version later than 5.4.7 and any 6.1.x version later than 6.1.2, published with the 2026-08-06 core security release. Until patched, restrict which privileged accounts can edit content and fields that feed schema.org structured-data output, and check whether your templates/components emit schema.org markup where injected script could reach other users. Because exploitation requires high privileges, review for shared or compromised admin accounts as an interim hardening step.
Affected
| Joomla! CMS | 5.1.0 – 5.4.7 |
| Joomla! CMS | 6.0.0 – 6.1.2 |
Estimated exposure
masslikely several hundred thousand to ≈1M+ sites (the affected 5.x/6.x branches are Joomla's current supported releases) — Public web-technology trackers such as BuiltWith and W3Techs place Joomla's live installed base at roughly 1–2 million sites, and with Joomla 5/6 representing the current supported branches, a large share of maintained installs plausibly…
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.