Review reviewHigh
CVE-2026-48901
Joomla! Project Joomla! CMS, joomla!
The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.
- CVSS
- 7.5
- EPSS
- 0.24% 15.8% percentile
- CISA KEV
- Not listed
- Published
- 2026.05.27