CVE-2026-60034 CRITICAL

CVE-2026-60034: Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0

Vendor Themexpert.com
Product JMedia extension for Joomla
Weakness CWE-79 · XSS
Published July 20, 2026
Last update July 23, 2026

CVSS base score

9.4/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.

Explanation of Vulnerability in Simple Terms

02Summary

The JMedia extension for Joomla contains a cross-site scripting (XSS) vulnerability that allows high-privileged users to inject malicious scripts. An attacker with administrative or elevated permissions can craft input that executes JavaScript in other users' browsers, potentially compromising site security or stealing session data. Update to a version newer than 1.5.4.

What an attacker can do

03Attacker Capabilities

Inject and execute malicious JavaScript in other users' browsers via the vulnerable component.

Potential impact on your site

04Site Impact

A compromised admin account could inject scripts affecting all site visitors, risking data theft or malware distribution.

Conditions required to exploit

05Prerequisites

Attacker must have high-level privileges (admin or equivalent role) on the Joomla site.

Key dates

06Disclosure timeline

July 20, 2026 CVE published
July 23, 2026 Record updated

Related vulnerabilities

08Related CVE