Joomla · 4Analytics · CVE-2026-58077
**Name of the Vulnerable Software and Affected Versions**
4Analytics (affected versions not specified)
**Description**
The Joomla extension 4Analytics contains an unauthenticated stored Cross-Site Scripting (XSS) flaw. A stored XSS occurs when a malicious script is permanently stored on the target server, which is then served to other users. An unauthenticated request containing a specially crafted payload can lead to a full website takeover under certain conditions.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.