ZeroHour

CVE-2026-73336

mass

Stored XSS via schema.org markup output in Joomla! core 5.1.0–5.4.7 and 6.0.0–6.1.2

CVSS 4.0
5.1 medium
EPSS
<1%p9
Published
()
Modified
AI analysis

Joomla! core contains a cross-site scripting flaw (CWE-79) in which improperly set escaping flags allow malicious markup to pass unescaped into the schema.org structured-data output that the CMS renders on pages. An attacker who already holds elevated privileges on the site (the CVSS 4.0 vector requires high privileges, PR:H) can plant content or fields that the schema.org emitter then outputs without escaping, so attacker-supplied JavaScript executes in the browsers of anyone loading the affected pages, with no additional user interaction required. The practical gain is script execution in victims' session contexts, though the 5.1 medium CVSS 4.0 score indicates low-impact confidentiality and integrity effects rather than full system compromise. All sites running Joomla! 5.1.0 through 5.4.7 or 6.0.0 through 6.1.2 are affected. No public proof-of-concept is known, the issue is not in the CISA KEV catalog, and EPSS estimates only about a 0.2% chance of exploitation in the next 30 days, so no exploitation is currently known.

What to do: Upgrade Joomla! core to a release above the affected ranges — any 5.4.x version later than 5.4.7 and any 6.1.x version later than 6.1.2, published with the 2026-08-06 core security release. Until patched, restrict which privileged accounts can edit content and fields that feed schema.org structured-data output, and check whether your templates/components emit schema.org markup where injected script could reach other users. Because exploitation requires high privileges, review for shared or compromised admin accounts as an interim hardening step.

Affected
Joomla! CMS5.1.0 – 5.4.7
Joomla! CMS6.0.0 – 6.1.2
Estimated exposure
masslikely several hundred thousand to ≈1M+ sites (the affected 5.x/6.x branches are Joomla's current supported releases) — Public web-technology trackers such as BuiltWith and W3Techs place Joomla's live installed base at roughly 1–2 million sites, and with Joomla 5/6 representing the current supported branches, a large share of maintained installs plausibly…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla! Core - [20260806] - XSS through schema.org outputs in Joomla 5.1.0-5.4.7, 6.0.0-6.1.2 - Improper escaping flags lead to an XSS vector in schema.org markup outputs.

Vendors
joomla
Products
joomla\!
Ecosystems
Joomla
Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

[20260806] - Core - XSS through schema.org outputs

Joomla fixed CVE-2026-73336, an XSS in schema.org markup outputs caused by improper escaping, affecting CMS 5.1.0-5.4.7 and 6.0.0-6.1.2.

Joomla security advisory 20260806 describes CVE-2026-73336, a cross-site scripting issue in schema.org markup outputs. Improper escaping flags create an XSS vector in schema.org output; the vendor rates impact and severity as moderate with low probability. Affected versions are 5.1.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by Amin Isayev and Geo (GitHub.com/geo-chen) on 2026-07-21.

Joomla Security Centre · 29d agoAdvisoryCVE-2026-73336