CVE-2026-78302

Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly into HTML without contextual escaping.
CVSS

No CVSS.

Configurations

No configuration.

History

No history.

Information

Published : 2026-09-10 10:17

Updated : 2026-09-10 15:13


NVD link : CVE-2026-78302

Mitre link : CVE-2026-78302

CVE.ORG link : CVE-2026-78302


JSON object : View

Products Affected

No product.

CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')