CVE-2025-54476

MEDIUM

Joomla Filter 4.0.0-4.0.1 - Cross-Site Scripting in checkAttribute Method

Title source: llm
STIX 2.1

Description

Improper handling of input could lead to an XSS vector in the checkAttribute method of the input filter framework class.

Scores

CVSS v4 4.8
EPSS 0.0005
EPSS Percentile 16.1%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-79
Status published
Products (1)
joomla/filter 4.0.0 - 4.0.1Packagist
Published Sep 30, 2025
Tracked Since Feb 18, 2026