Weekly roundup
Open-source business platforms, week 40 of 2026: high-severity Joomla flaws lead 30 advisories
The maintainers of Joomla!, Moodle and Frappe/ERPNext published 30 vulnerabilities this week, 28 with CVE ids. Seven are high severity, led by a Joomla SSRF and an MFA bypass. No KEV or known exploitation. Patch Joomla first, then Moodle and Frappe.
The release at a glance
The maintainers of Joomla!, Moodle and Frappe/ERPNext published 30 vulnerabilities covering the week of 28 September to 4 October 2026. Of these, 28 carry CVE identifiers and 2 are GHSA advisories. The release includes 7 high-severity, 18 medium-severity, 4 low-severity and 1 unscored issue. By product, Joomla! accounts for 16 advisories, Moodle for 12, and Frappe/ERPNext for 2. No vulnerability in this release is listed in CISA KEV, and no known exploitation is reported.
The main priority is Joomla! CMS, where a high-scoring SSRF, an MFA bypass and several access-control flaws sit alongside input-filter issues. Moodle's highest-profile item is a CSRF flaw in XML grade import. For the two Frappe Framework advisories, one is medium severity and one unscored; no fixed versions are listed.
What matters most
In Joomla! CMS, CVE-2026-92222 is an SSRF in various core extensions with a CVSS 4.0 score of 8.9; it is fixed in Joomla! CMS 5.4.9 and 6.1.4. CVE-2026-92227 is an MFA authentication bypass through remember-me cookies, CVSS 4.0 8.2, network-reachable with no privileges required. CVE-2026-92232 and CVE-2026-92231 are separate XSS filter bypasses in InputFilter, each scored CVSS 4.0 7.1; they affect Joomla! CMS and the Joomla! Framework Filter package. CVE-2026-90913 and CVE-2026-92226 are improper ACL checks in webservice endpoints and edit tasks, each scored CVSS 4.0 7.0. CVE-2026-90915 allows arbitrary directory deletion via the cache purge action, CVSS 4.0 7.0. The Joomla CVEs in this group have their own advisory pages on this site.
In Moodle, CVE-2026-102588 is a CSRF flaw in XML grade import, scored CVSS 3.1 6.5. An attacker can trick an authenticated user with grade-management permissions into triggering unauthorized grade writes. Moodle lists 5.2.2, 5.1.6, 5.0.9 and 4.5.13 as fixed versions.
Patch in this order
- Patch Joomla! CMS first, particularly internet-facing sites, to Joomla! CMS 5.4.9 or 6.1.4. Start with CVE-2026-92222, CVE-2026-92227, CVE-2026-92232, CVE-2026-92231, CVE-2026-90913, CVE-2026-92226 and CVE-2026-90915, then apply the remaining Joomla advisories in the release.
- If you use the Joomla! Framework Filter package outside the CMS, review its exposure to CVE-2026-92232 and CVE-2026-92231; the release lists affected package ranges but no separate package fix.
- Patch Moodle to the fixed branches for CVE-2026-102588: 5.2.2, 5.1.6, 5.0.9 or 4.5.13. Review the other Moodle medium and low issues in the same maintenance window.
- Review the two Frappe/ERPNext advisories, GHSA-h9jq-7pgf-hw8q and GHSA-wrh5-p77r-jpvq. No fixed versions are listed for them, so confirm the project guidance and your deployment details.
- Schedule the remaining medium and low Joomla and Moodle fixes for the next normal patching window; none are listed in CISA KEV.
Beyond the patch
This kind of week is manageable when the platform inventory and the public-facing footprint are already known: the fixes are maintainer version updates, and the immediate risk is on internet-facing Joomla and Moodle deployments. For a public website or shop platform, Implementation & Assessment Services can run a penetration test and hardening review to confirm what an attacker can reach. For teams running several open-source business platforms, Supply Chain Defense & Third-Party Risk tracks which platforms and versions you depend on and how quickly their maintainers publish fixes, so the next advisory cycle becomes a planned patching list.
Every advisory in this release
| ID | Product | Severity | |
|---|---|---|---|
| CVE-2026-92222 | Joomla! CMS | High 8.9 | Advisory → |
| CVE-2026-92227 | Joomla! CMS | High 8.2 | Advisory → |
| CVE-2026-92232 | Joomla! CMS | High 7.1 | Advisory → |
| CVE-2026-92231 | Joomla! CMS | High 7.1 | Advisory → |
| CVE-2026-90913 | Joomla! CMS | High 7.0 | Advisory → |
| CVE-2026-92226 | Joomla! CMS | High 7.0 | Advisory → |
| CVE-2026-90915 | Joomla! CMS | High 7.0 | Advisory → |
| CVE-2026-90917 | Joomla! CMS | Medium 6.9 | Advisory → |
| CVE-2026-90918 | Joomla! CMS | Medium 6.9 | Advisory → |
| CVE-2026-90907 | Joomla! CMS | Medium 6.9 | Advisory → |
| CVE-2026-102588 | Medium 6.5 | ||
| CVE-2026-90906 | Joomla! CMS | Medium 5.9 | |
| CVE-2026-92225 | Joomla! CMS | Medium 5.9 | |
| CVE-2026-90914 | Joomla! CMS | Medium 5.9 | |
| CVE-2026-92224 | Joomla! CMS | Medium 5.9 | |
| CVE-2026-102578 | Medium 5.5 | ||
| GHSA-h9jq-7pgf-hw8q | Frappe Framework | Medium 5.4 | |
| CVE-2026-90916 | Joomla! CMS | Medium 5.1 | |
| CVE-2026-92223 | Joomla! CMS | Medium 5.1 | |
| CVE-2026-102581 | Medium 4.6 | ||
| CVE-2026-102577 | Medium 4.3 | ||
| CVE-2026-102579 | Medium 4.3 | ||
| CVE-2026-102584 | Medium 4.3 | ||
| CVE-2026-102585 | Medium 4.3 | ||
| CVE-2026-102586 | Medium 4.3 | ||
| CVE-2026-102583 | Low 2.7 | ||
| CVE-2026-102587 | Low 2.7 | ||
| CVE-2026-102580 | Low 2.2 | ||
| CVE-2026-102582 | Low 2.2 | ||
| GHSA-wrh5-p77r-jpvq | Frappe Framework | Not scored |
References
Vendor advisory
- Joomla! security announcement [20260909]: SSRF vectors in various core extensions
- Joomla! security announcement [20260914]: MFA Authentication Bypass through rememberme …
- Joomla! security announcement [20260916]: XSS filter bypass in InputFilter via whitespa…
- Joomla! security announcement [20260915]: XSS filter bypass in InputFilter via HTML5 en…
- Joomla! security announcement [20260903]: Improper ACL checks for access level webservi…
- Joomla! security announcement [20260913]: Improper ACL checks for varous webservice edi…
- Joomla! security announcement [20260905]: Arbitrary directory deletion via cache purge …
- Joomla! security announcement [20260907]: Improper ACL checks in outputs for tagged items
Patch and release notes
CVE
- CVE-2026-92222 — cve.org
- CVE-2026-92222 — NVD
- EUVD-2026-89079 — ENISA EUVD
- CVE-2026-92227 — cve.org
- CVE-2026-92227 — NVD
- EUVD-2026-89074 — ENISA EUVD
- CVE-2026-92232 — cve.org
- CVE-2026-92232 — NVD
- EUVD-2026-89073 — ENISA EUVD
- CVE-2026-92231 — cve.org
- CVE-2026-92231 — NVD
- EUVD-2026-89082 — ENISA EUVD
- CVE-2026-90913 — cve.org
- CVE-2026-90913 — NVD
- EUVD-2026-89115 — ENISA EUVD
- CVE-2026-92226 — cve.org
- CVE-2026-92226 — NVD
- EUVD-2026-89087 — ENISA EUVD
- CVE-2026-90915 — cve.org
- CVE-2026-90915 — NVD
- EUVD-2026-89088 — ENISA EUVD
- CVE-2026-90917 — cve.org
- CVE-2026-90917 — NVD
- EUVD-2026-89076 — ENISA EUVD
- CVE-2026-90918 — cve.org
- CVE-2026-90918 — NVD
- EUVD-2026-89080 — ENISA EUVD
- CVE-2026-90907 — cve.org
- CVE-2026-90907 — NVD
- EUVD-2026-89085 — ENISA EUVD
- CVE-2026-102588 — cve.org
- CVE-2026-102588 — NVD
- EUVD-2026-89727 — ENISA EUVD
- CVE-2026-90906 — cve.org
- CVE-2026-90906 — NVD
- EUVD-2026-89114 — ENISA EUVD