What the vulnerability does
01Description
Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.
Explanation of Vulnerability in Simple Terms
02Summary
The JMedia extension for Joomla contains a cross-site scripting (XSS) vulnerability that allows high-privileged users to inject malicious scripts. An attacker with administrative or elevated permissions can craft input that executes JavaScript in other users' browsers, potentially compromising site security or stealing session data. Update to a version newer than 1.5.4.
What an attacker can do
03Attacker Capabilities
Inject and execute malicious JavaScript in other users' browsers via the vulnerable component.
Potential impact on your site
04Site Impact
A compromised admin account could inject scripts affecting all site visitors, risking data theft or malware distribution.
Conditions required to exploit
05Prerequisites
Attacker must have high-level privileges (admin or equivalent role) on the Joomla site.
Key dates
06Disclosure timeline
July 20, 2026
CVE published
July 23, 2026
Record updated