AI analysis
Joomla! Core 5.1.0 through 5.4.7 and 6.0.0 through 6.1.2 contain an improper access-control check (CWE-284) in the code that injects schema.org contact data into pages. When such a page is generated, the flawed check pulls in contact information from contact items the viewer is not authorized to see, embedding it in the schema.org snippet served to visitors. An attacker gains disclosure of contact details that should have been restricted; the CVSS 4.0 score of 5.1 (medium) reflects this low-confidentiality, network-exploitable issue with no impact on integrity or availability. Sites running the affected Joomla branches that render schema.org contact data are exposed, while installations on other versions or not using this feature are not. No public proof-of-concept exists, the issue is not in CISA's KEV catalog, and EPSS estimates a 0.2% probability of exploitation within 30 days, so no exploitation is currently known.
What to do: Update Joomla! Core to a release newer than the affected ranges (later than 5.4.7 on the 5.x branch and later than 6.1.2 on the 6.x branch) per the Joomla security advisory dated 2026-08-09. As an interim mitigation, disable or reconfigure schema.org contact-data output and review whether restricted contact items have been exposed in snippets. No active exploitation is known, but defenders monitoring Joomla estates should prioritize the update since the affected branches are current major versions.
Affected
| Joomla! Core | 5.1.0 - 5.4.7 |
| Joomla! Core | 6.0.0 - 6.1.2 |
Estimated exposure
mass≈2-3 million Joomla installations, with only the subset using the contacts component / schema.org output actually leaking data — Joomla powers roughly 1-2% of all websites per public web-technology surveys (W3Techs), implying millions of live installs in the affected version ranges, though exposure to this flaw is limited to sites that render schema.org contact data.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.