Joomla · Chronoforms · CVE-2026-58148
**Name of the Vulnerable Software and Affected Versions**
ChronoForms versions 8.0 through 8.0.52
**Description**
The ChronoForms extension for Joomla contains a stored Cross-Site Scripting (XSS) flaw. This issue allows an unauthenticated attacker to inject malicious scripts that are stored on the server and subsequently executed in the browser of other users.
**Recommendations**
Update ChronoForms to a version later than 8.0.52.