SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-78302

HIGH · CVSS 8.6 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-10 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Joomla Extension from joomshaper.com is vulnerable to unauthenticated stored cross-site scripting (XSS) due to unescaped output in multiple template files within SP Property versions prior to 4.1.4. This vulnerability allows attackers to inject malicious scripts into web pages, potentially compromising user data and site integrity. Joomla administrators and developers using affected versions should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-78302
Severity
HIGH
CVSS
8.6
EPSS
0.26%

Original NVD Description

Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly into HTML without contextual escaping.