Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-60034: Joomla JMedia Extension: Unsecured SVG Uploads Cause Harmful Code Injection
CVE-2026-60034
CVE-2026-60034
Summary
The JMedia extension for Joomla allows attackers to inject malicious code into websites through unsanitised SVG uploads. This can happen when a user with administrative access uploads a malicious SVG file. To fix this, update the JMedia extension to version 1.6.0 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| themexpert.com | jmedia extension for joomla | 1.0-1.5.4 |
Original title
Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0
Original description
The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.
Vulnerability type
CWE-79
Cross-site Scripting (XSS)
Published: 20 Jul 2026 · Updated: 21 Jul 2026 · First seen: 20 Jul 2026