PT-2026-60784 · Joomla · Chronoforms
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
ChronoForms versions 8.0 through 8.0.52
Description
The ChronoForms extension for Joomla contains a stored Cross-Site Scripting (XSS) flaw. This issue allows an unauthenticated attacker to inject malicious scripts that are stored on the server and subsequently executed in the browser of other users.
Recommendations
Update ChronoForms to a version later than 8.0.52.
Fix
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Chronoforms