CVE Watchtower ← Back to CVE ListCVE-2026-60034NVDVulnerability SummaryThe Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.Severity LevelUNKNOWNPublished DateJul 20, 2026Last ModifiedJul 21, 2026Exploitation StatusNo confirmed exploitation yetEPSS Score (30-Day)Data PendingRoot Weakness (CWE)N/AExternal Referenceshttps://www.themexpert.com/joomla-extensions/joomla-media-manager