SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-65882

MEDIUM · CVSS 6.1 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The Joomdle extension for Joomla versions prior to 3.1.1 is vulnerable to a reflected cross-site scripting (XSS) attack via the "goto" URL parameter in the Moodle wrapper endpoint. This vulnerability could allow attackers to execute arbitrary scripts in the context of the user's session, potentially leading to session hijacking or data theft. Joomla administrators using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-65882
Severity
MEDIUM
CVSS
6.1
EPSS
0.15%

Original NVD Description

Joomla Extension - joomdle.com - Reflected XSS vulnerability in Joomdle < 3.1.1 - The goto url parameter of the moodle wrapper endpoint allowed a reflected XSS vector.