Joomla · Joomla! · CVE-2026-71572
**Name of the Vulnerable Software and Affected Versions**
Joomla! Core versions 3.0.0 through 5.4.7
Joomla! Core versions 6.0.0 through 6.1.2
**Description**
Lack of output processing in multiple download views allows for response header injection. This issue can lead to reflected file download or content-type confusion, where the browser is misled about the nature of the file being downloaded.
**Recommendations**
Update Joomla! Core versions 3.0.0 through 5.4.7 to a version newer than 5.4.7.
Update Joomla! Core versions 6.0.0 through 6.1.2 to a version newer than 6.1.2.