Skip to content

Weekly roundup

Open-source business platforms, week 40 of 2026: high-severity Joomla flaws lead 30 advisories

High 8.9 Vendor: Open-source business platforms 30 advisories in scope Published

The maintainers of Joomla!, Moodle and Frappe/ERPNext published 30 vulnerabilities this week, 28 with CVE ids. Seven are high severity, led by a Joomla SSRF and an MFA bypass. No KEV or known exploitation. Patch Joomla first, then Moodle and Frappe.

The release at a glance

The maintainers of Joomla!, Moodle and Frappe/ERPNext published 30 vulnerabilities covering the week of 28 September to 4 October 2026. Of these, 28 carry CVE identifiers and 2 are GHSA advisories. The release includes 7 high-severity, 18 medium-severity, 4 low-severity and 1 unscored issue. By product, Joomla! accounts for 16 advisories, Moodle for 12, and Frappe/ERPNext for 2. No vulnerability in this release is listed in CISA KEV, and no known exploitation is reported.

The main priority is Joomla! CMS, where a high-scoring SSRF, an MFA bypass and several access-control flaws sit alongside input-filter issues. Moodle's highest-profile item is a CSRF flaw in XML grade import. For the two Frappe Framework advisories, one is medium severity and one unscored; no fixed versions are listed.

What matters most

In Joomla! CMS, CVE-2026-92222 is an SSRF in various core extensions with a CVSS 4.0 score of 8.9; it is fixed in Joomla! CMS 5.4.9 and 6.1.4. CVE-2026-92227 is an MFA authentication bypass through remember-me cookies, CVSS 4.0 8.2, network-reachable with no privileges required. CVE-2026-92232 and CVE-2026-92231 are separate XSS filter bypasses in InputFilter, each scored CVSS 4.0 7.1; they affect Joomla! CMS and the Joomla! Framework Filter package. CVE-2026-90913 and CVE-2026-92226 are improper ACL checks in webservice endpoints and edit tasks, each scored CVSS 4.0 7.0. CVE-2026-90915 allows arbitrary directory deletion via the cache purge action, CVSS 4.0 7.0. The Joomla CVEs in this group have their own advisory pages on this site.

In Moodle, CVE-2026-102588 is a CSRF flaw in XML grade import, scored CVSS 3.1 6.5. An attacker can trick an authenticated user with grade-management permissions into triggering unauthorized grade writes. Moodle lists 5.2.2, 5.1.6, 5.0.9 and 4.5.13 as fixed versions.

Patch in this order

  1. Patch Joomla! CMS first, particularly internet-facing sites, to Joomla! CMS 5.4.9 or 6.1.4. Start with CVE-2026-92222, CVE-2026-92227, CVE-2026-92232, CVE-2026-92231, CVE-2026-90913, CVE-2026-92226 and CVE-2026-90915, then apply the remaining Joomla advisories in the release.
  2. If you use the Joomla! Framework Filter package outside the CMS, review its exposure to CVE-2026-92232 and CVE-2026-92231; the release lists affected package ranges but no separate package fix.
  3. Patch Moodle to the fixed branches for CVE-2026-102588: 5.2.2, 5.1.6, 5.0.9 or 4.5.13. Review the other Moodle medium and low issues in the same maintenance window.
  4. Review the two Frappe/ERPNext advisories, GHSA-h9jq-7pgf-hw8q and GHSA-wrh5-p77r-jpvq. No fixed versions are listed for them, so confirm the project guidance and your deployment details.
  5. Schedule the remaining medium and low Joomla and Moodle fixes for the next normal patching window; none are listed in CISA KEV.

Beyond the patch

This kind of week is manageable when the platform inventory and the public-facing footprint are already known: the fixes are maintainer version updates, and the immediate risk is on internet-facing Joomla and Moodle deployments. For a public website or shop platform, Implementation & Assessment Services can run a penetration test and hardening review to confirm what an attacker can reach. For teams running several open-source business platforms, Supply Chain Defense & Third-Party Risk tracks which platforms and versions you depend on and how quickly their maintainers publish fixes, so the next advisory cycle becomes a planned patching list.

Every advisory in this release

IDProductSeverity
CVE-2026-92222Joomla! CMSHigh 8.9Advisory →
CVE-2026-92227Joomla! CMSHigh 8.2Advisory →
CVE-2026-92232Joomla! CMSHigh 7.1Advisory →
CVE-2026-92231Joomla! CMSHigh 7.1Advisory →
CVE-2026-90913Joomla! CMSHigh 7.0Advisory →
CVE-2026-92226Joomla! CMSHigh 7.0Advisory →
CVE-2026-90915Joomla! CMSHigh 7.0Advisory →
CVE-2026-90917Joomla! CMSMedium 6.9Advisory →
CVE-2026-90918Joomla! CMSMedium 6.9Advisory →
CVE-2026-90907Joomla! CMSMedium 6.9Advisory →
CVE-2026-102588Medium 6.5
CVE-2026-90906Joomla! CMSMedium 5.9
CVE-2026-92225Joomla! CMSMedium 5.9
CVE-2026-90914Joomla! CMSMedium 5.9
CVE-2026-92224Joomla! CMSMedium 5.9
CVE-2026-102578Medium 5.5
GHSA-h9jq-7pgf-hw8qFrappe FrameworkMedium 5.4
CVE-2026-90916Joomla! CMSMedium 5.1
CVE-2026-92223Joomla! CMSMedium 5.1
CVE-2026-102581Medium 4.6
CVE-2026-102577Medium 4.3
CVE-2026-102579Medium 4.3
CVE-2026-102584Medium 4.3
CVE-2026-102585Medium 4.3
CVE-2026-102586Medium 4.3
CVE-2026-102583Low 2.7
CVE-2026-102587Low 2.7
CVE-2026-102580Low 2.2
CVE-2026-102582Low 2.2
GHSA-wrh5-p77r-jpvqFrappe FrameworkNot scored

References

CVE

Sources: the CVE record (MITRE), NVD, CISA KEV and SSVC, ENISA EUVD, FIRST EPSS and the vendor's own advisory. Scores and dates are shown as those sources publish them. Entries marked GHSA have no CVE: their source is the security advisory the maintainers published in their official GitHub repository.

Written with AI assistance from the sources above and checked automatically against them before publication.