SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65756

MEDIUM · CVSS 6.1 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The Keyboard Shortcuts extension for Joomla is vulnerable to a cross-site scripting (XSS) attack due to its acceptance of arbitrary inline JavaScript in shortcut configurations. This flaw could allow attackers to execute malicious scripts in the context of a user's session, potentially leading to data theft or session hijacking. Joomla administrators and users of the affected extension should prioritize patching or mitigating this vulnerability to protect their applications from exploitation.

CVE
CVE-2026-65756
Severity
MEDIUM
CVSS
6.1
EPSS
0.15%
Java

Original NVD Description

Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.