CVE-2026-48901

The InputFilter::getInstance() method omitted a security sensitive parameter from the instance cache key.

high 7.5 CVSS 3.1
Published: May 26, 2026
Modified: May 28, 2026
Vendor: Joomla
Product: Joomla\!