{"id":"CVE-2026-90906","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-90906","summary":"Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3","details":"Joomla! Core - [20260901] - XSS in HTMLHelper::link method in Joomla 1.5.0-5.4.8, 6.0.0-6.1.3 - Lack of escaping leads to XSS vulnerabilities in the link method of the HTML Helper.","published":"2026-10-07T11:45:34.269Z","modified":"2026-10-07T14:30:05.028017799Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[{"ecosystem":"Bitnami","name":"joomla","fixedVersion":"5.4.8"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://developer.joomla.org/security-centre/1081-20260901-core-xss-in-htmlhelper-link-method.html"},{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-90906"},{"type":"WEB","url":"https://www.joomla.org/"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-10-07T14:30:05.028017799Z"}}