CVE-2026-92222
Received Received - Intake

Server-Side Request Forgery in Joomla Core Extensions

Vulnerability report for CVE-2026-92222, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-29

Last updated on: 2026-09-29

Assigner: Joomla! Project

Description

Joomla! Core - [20260909] - Core - SSRF vectors in various core extensions in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - URLs used for serverside requests were improperly validated, leading to SSRF vectors.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-29
Last Modified
2026-09-29
Generated
2026-09-29
AI Q&A
2026-09-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
joomla joomla From 4.0.0 (inc) to 5.4.8 (inc)
joomla joomla From 6.0.0 (inc) to 6.1.3 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-918 The web server receives a URL or similar request from an upstream component and retrieves the contents of this URL, but it does not sufficiently ensure that the request is being sent to the expected destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Server-Side Request Forgery (SSRF) issue in Joomla! Core affecting versions 4.0.0-5.4.8 and 6.0.0-6.1.3. It occurs because URLs used for server-side requests are not properly validated, allowing attackers to manipulate requests to unintended internal or external systems.

Detection Guidance

To detect this vulnerability, check if your Joomla! CMS version is within the affected range (4.0.0-5.4.8 or 6.0.0-6.1.3). Use commands like 'composer show joomla/joomla' or check the Joomla admin panel for version details. If vulnerable, upgrade to versions 5.4.9 or 6.1.4 immediately.

Impact Analysis

An attacker could exploit this to access internal systems, bypass firewalls, or interact with other services on your network. This may lead to data theft, unauthorized actions, or further compromise of your Joomla! installation or connected systems.

Compliance Impact

This SSRF vulnerability could result in unauthorized data access or exfiltration, violating GDPR's data protection principles or HIPAA's security requirements. Non-compliance may lead to legal penalties, fines, or reputational damage.

Mitigation Strategies

Update Joomla to the latest patched version (5.4.9 or later for Joomla 4.x, 6.1.4 or later for Joomla 6.x) to address SSRF vectors in core extensions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92222. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart