ZeroHour
Joomla Security Centrepublished ()ingested [email protected] (Joomla! Security Strike Team)

[20260806] - Core - XSS through schema.org outputs

mediumAdvisoryimportance 30CVE-2026-73336
AI summary · glm-5.3-flash

Joomla fixed CVE-2026-73336, an XSS in schema.org markup outputs caused by improper escaping, affecting CMS 5.1.0-5.4.7 and 6.0.0-6.1.2.

Joomla security advisory 20260806 describes CVE-2026-73336, a cross-site scripting issue in schema.org markup outputs. Improper escaping flags create an XSS vector in schema.org output; the vendor rates impact and severity as moderate with low probability. Affected versions are 5.1.0-5.4.7 and 6.0.0-6.1.2; fixes ship in 5.4.8 and 6.1.3. The issue was reported by Amin Isayev and Geo (GitHub.com/geo-chen) on 2026-07-21.

  • Improper escaping flags enable XSS in schema.org markup outputs
  • Affects Joomla CMS 5.1.0-5.4.7 and 6.0.0-6.1.2
  • Fixed in Joomla 5.4.8 and 6.1.3
VendorsJoomla
ProductsJoomla CMS
OrganizationsJoomla

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2026-73336
Stored XSS via schema.org markup output in Joomla! core 5.1.0–5.4.7 and 6.0.0–6.1.2

Joomla! core contains a cross-site scripting flaw (CWE-79) in which improperly set escaping flags allow malicious markup to pass unescaped into the schema.org structured-data output that the CMS renders on pages. An attacker who already holds elevated privileges on the site (the CVSS 4.0 vector requires high privileges, PR:H) can plant content or fields that the schema.org emitter then outputs without escaping, so attacker-supplied JavaScript executes in the browsers of anyone loading the affected pages, with no additional user interaction required. The practical gain is script execution in victims' session contexts, though the 5.1 medium CVSS 4.0 score indicates low-impact confidentiality and integrity effects rather than full system compromise. All sites running Joomla! 5.1.0 through 5.4.7 or 6.0.0 through 6.1.2 are affected. No public proof-of-concept is known, the issue is not in the CISA KEV catalog, and EPSS estimates only about a 0.2% chance of exploitation in the next 30 days, so no exploitation is currently known.

Do: Upgrade Joomla! core to a release above the affected ranges — any 5.4.x version later than 5.4.7 and any 6.1.x version later than 6.1.2, published with the 2026-08-06 core security release. Until patched, restrict which privileged accounts can edit content and fields that feed schema.org structured-data output, and check whether your templates/components emit schema.org markup where injected script could reach other users. Because exploitation requires high privileges, review for shared or compromised admin accounts as an interim hardening step.

5.1<1%
  • Joomla! CMS 5.1.0 – 5.4.7
  • Joomla! CMS 6.0.0 – 6.1.2
masslikely several hundred thousand to ≈1M+ sites (the affected 5.x/6.x branches are Joomla's current supported releases)
Full article

Project: Joomla! SubProject: CMS Impact: Moderate Severity: Moderate Probability: Low Versions: 5.1.0-5.4.7, 6.0.0-6.1.2 Exploit type: XSS Reported Date: 2026-07-21 Fixed Date: 2026-08-18 CVE Number: CVE-2026-73336 Description Improper escaping flags lead to an XSS vector in schema.org markup outputs. Affected Installs Joomla! CMS versions 5.1.0-5.4.7, 6.0.0-6.1.2 Solution Upgrade to version 5.4.8, 6.1.3 Contact The JSST at the Joomla! Security Centre. Reported By: Amin İsayev, Geo (GitHub.com/geo-chen)

This source does not provide full text. Read it at developer.joomla.org.