{"id":"CVE-2025-54476","aliases":[],"url":"https://o3.security/vulnerability/CVE-2025-54476","summary":"Joomla! CMS vulnerable to XSS via the input filter","details":"Improper handling of input could lead to a cross-site scripting (XSS) vector in the checkAttribute method of the input filter framework class.","published":"2025-09-30T18:30:24Z","modified":"2025-10-01T19:42:32.140260Z","cvss":null,"epss":{"score":0.00314,"percentile":0.24404,"asOf":"2026-09-17"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"Packagist","name":"joomla/filter","fixedVersion":"4.0.1"},{"ecosystem":"Packagist","name":"joomla/filter","fixedVersion":"3.0.5"},{"ecosystem":"Packagist","name":"joomla/filter","fixedVersion":"2.0.6"}],"fix":{"url":"https://github.com/joomla-framework/filter/commit/188dd3fccd6fa0532d105a52736affdf6b166217","label":"joomla-framework/filter@188dd3f"},"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-54476"},{"type":"WEB","url":"https://github.com/joomla-framework/filter/commit/188dd3fccd6fa0532d105a52736affdf6b166217"},{"type":"WEB","url":"https://github.com/joomla-framework/filter/commit/852c7e101c649500d3af58ffb8baf15d7c86d825"},{"type":"WEB","url":"https://github.com/joomla-framework/filter/commit/fcde280785f188e93530f7da68102f7dd8f9f723"},{"type":"WEB","url":"https://developer.joomla.org/security-centre/1010-20250901-core-inadequate-content-filtering-within-the-checkattribute-filter-code.html"},{"type":"PACKAGE","url":"https://github.com/joomla/joomla-cms"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2025-10-01T19:42:32.140260Z"}}