CVE-2026-48902: Joomla!
Critical severity, CVSS 9.8. EPSS: 0.3% chance of exploitation in the next 30 days.
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
Affected products
- Joomla! Joomla!: from 3.0.0, before 5.4.6 (fixed in 5.4.6); from 6.0.0, before 6.1.1 (fixed in 6.1.1)
Published 2026-05-26. Last modified 2026-07-24.