PT-2026-61681 · Joomla · Jmedia

CVE-2026-60034

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions JMedia versions prior to 1.6.0
Description The JMedia extension for Joomla contains a stored Cross-Site Scripting (XSS) flaw. This occurs because the application allows the upload of unsanitized SVG files which are then served without the nosniff header, enabling the execution of malicious scripts.
Recommendations Update JMedia to version 1.6.0 or later.

Fix

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60034

Affected Products

Jmedia