SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-77027

HIGH · CVSS 8.6 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-08-22 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The Fabrik extension for Joomla versions prior to 4.7.2 is vulnerable to an unauthenticated stored cross-site scripting (XSS) attack due to inadequate handling of user-supplied input in the jsactions feature. This vulnerability allows attackers to inject malicious scripts that can be executed in the context of users accessing the affected application, potentially compromising sensitive data and user sessions. Joomla administrators and web developers using this extension should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-77027
Severity
HIGH
CVSS
8.6
EPSS
0.26%

Original NVD Description

Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector.