{"id":"GHSA-fm22-g2q9-j3pw","summary":"Joomla! CMS vulnerable to XSS via the input filter","details":"Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class.","aliases":["CVE-2025-54476"],"modified":"2025-10-01T19:42:32.140260Z","published":"2025-09-30T18:30:24Z","database_specific":{"nvd_published_at":"2025-09-30T16:15:52Z","cwe_ids":["CWE-79"],"severity":"MODERATE","github_reviewed":true,"github_reviewed_at":"2025-10-01T19:30:21Z"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54476"},{"type":"WEB","url":"https://github.com/joomla-framework/filter/commit/188dd3fccd6fa0532d105a52736affdf6b166217"},{"type":"WEB","url":"https://github.com/joomla-framework/filter/commit/852c7e101c649500d3af58ffb8baf15d7c86d825"},{"type":"WEB","url":"https://github.com/joomla-framework/filter/commit/fcde280785f188e93530f7da68102f7dd8f9f723"},{"type":"WEB","url":"https://developer.joomla.org/security-centre/1010-20250901-core-inadequate-content-filtering-within-the-checkattribute-filter-code.html"},{"type":"PACKAGE","url":"https://github.com/joomla/joomla-cms"}],"affected":[{"package":{"name":"joomla/filter","ecosystem":"Packagist","purl":"pkg:composer/joomla/filter"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"4.0.0"},{"fixed":"4.0.1"}]}],"versions":["4.0.0"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-fm22-g2q9-j3pw/GHSA-fm22-g2q9-j3pw.json"}},{"package":{"name":"joomla/filter","ecosystem":"Packagist","purl":"pkg:composer/joomla/filter"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"3.0.0"},{"fixed":"3.0.5"}]}],"versions":["3.0.0","3.0.1","3.0.2","3.0.3","3.0.4"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-fm22-g2q9-j3pw/GHSA-fm22-g2q9-j3pw.json"}},{"package":{"name":"joomla/filter","ecosystem":"Packagist","purl":"pkg:composer/joomla/filter"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.0.6"}]}],"versions":["1.0","1.0-alpha","1.0-beta","1.0-beta2","1.0-beta3","1.1.0","1.1.1","1.1.2","1.1.3","1.1.4","1.1.5","1.1.6","1.2.0","1.3.0","1.3.1","1.3.2","1.3.3","1.3.4","1.3.5","1.4.0","1.4.1","1.4.2","1.4.3","1.4.4","1.4.5","1.4.6","1.4.7","2.0.0","2.0.0-beta","2.0.0-beta2","2.0.0-beta3","2.0.0-beta4","2.0.0-beta5","2.0.0-rc","2.0.1","2.0.2","2.0.3","2.0.4","2.0.5"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2025/09/GHSA-fm22-g2q9-j3pw/GHSA-fm22-g2q9-j3pw.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N"}]}