CVE-2026-71572

Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2

Joomla! Core - [20260801] - Response header injection in download views in Joomla 3.0.0-5.4.7, 6.0.0-6.1.2 - Lack of output processing allowed a header injection in the multiple download views, leading to reflected file download / content-type confusion.


We have discovered 4,501 live websites that are affected by CVE-2026-71572.

Run a Free Instant Scan




Affected Software

Product  Joomla
Category Content Management System
Vulnerable Domains4,501 live websites (3.37% of Joomla install base)
Vulnerable Versions
  • from 3 through 5.4.7
  • from 6 through 6.1.3
Vulnerable Versions Count110 versions ( 85% of all versions)


Common Weakness Enumeration

CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection')



Details

  • Published - Aug 18, 2026
  • Updated - Aug 19, 2026

Credits

  • arib06 (finder)

Website Distribution by Country

Number of websites using CVE-2026-71572
United States636 websites



Germany1,033 websites
France387 websites
Italy323 websites
Russia304 websites
Switzerland209 websites
Netherlands208 websites
Poland145 websites
Austria127 websites
GB125 websites

Website Distribution by TLD

Number of websites using CVE-2026-71572
.com927 websites
.de847 websites
.ru258 websites
.it225 websites
.fr212 websites
.org211 websites
.nl185 websites
.ch181 websites
.at127 websites
.net119 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2026-71572

Top websites that are affected by CVE-2026-71572. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
******.fr Canada**,***
************.ru Russia**,***
******.**.il Israel**,***
**.******.org United States**,***
*********************.com United States***,***
*****************.***.pl Poland***,***
**************.com France***,***
******.net United States***,***
***************.************.de Germany***,***
*****************.eu Germany***,***
See full domain list

FAQ

CVE-2026-71572 is Improper Neutralization of CRLF Sequences ('CRLF Injection') in Joomla
A total of 4,501 websites have been identified as vulnerable to CVE-2026-71572, based on global website indexing conducted by WebTechSurvey.
The Joomla is affected by the CVE-2026-71572 vulnerability.
Joomla versions up to 6.1.3 are vulnerable to CVE-2026-71572.
CVE-2026-71572 is resolved in version 6.1.3 of Joomla.