What is CVE-2026-73336?
This CVE describes an XSS (Cross-Site Scripting) vulnerability in Joomla! Core caused by improper escaping flags in schema.org markup outputs. The issue affects Joomla versions from 5.1.0 through 5.4.7 and 6.0.0 through 6.1.2. Users are strongly advised to immediately apply the latest security updates to mitigate this vulnerability.
Azərbaycanca: Bu CVE Joomla! Core-da schema.org çıxışlarında düzgün qorunma (escaping) bayraqlarının tətbiq edilməməsi nəticəsində yaranan XSS (Cross-Site Scripting) zəifliyini təsvir edir. Problem Joomla-nın 5.1.0-dan 5.4.7-yə və 6.0.0-dan 6.1.2-yə qədər olan versiyalarına təsir edir. Bu zəiflikdən qorunmaq üçün istifadəçilərə dərhal ən son təhlükəsizlik yeniləmələrini tətbiq etmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Joomla
FAQ2
Which versions of Joomla are affected by CVE-2026-73336?
This vulnerability affects Joomla! Core versions from 5.1.0 through 5.4.7 and from 6.0.0 through 6.1.2.
What type of vulnerability is CVE-2026-73336?
It is an XSS (Cross-Site Scripting) vulnerability caused by improper escaping flags in schema.org markup outputs.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.