55 CVEs categorized as CWE-79 — Cross-site Scripting (XSS) in Joomla.
CVE-2026-23900MEDIUM2026
Various stored XSS vulnerabilities in the maps- and icon rendering logic in Phoca Maps component 5.0.0-6.0.2 have been discovered.
CVE-2026-21632MEDIUM2026
Lack of output escaping for article titles leads to XSS vectors in various locations.
CVE-2026-21631MEDIUM2026
Lack of output escaping leads to a XSS vector in the multilingual associations component.
CVE-2026-21624CRITICAL2026
Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.
CVE-2026-21623CRITICAL2026
Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.
CVE-2025-63083MEDIUM2025
Lack of output escaping leads to a XSS vector in the pagebreak plugin.
CVE-2025-63082MEDIUM2025
Lack of input filtering leads to an XSS vector in the HTML filter code related to data URLs in img tags.
CVE-2025-55757MEDIUM2025
A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered.
CVE-2025-54476MEDIUM2025
Improper handling of input could lead to an XSS vector in the checkAttribute method of the input filter framework class.
CVE-2025-54301HIGH2025
A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. File names are not properly escaped.
CVE-2025-54300HIGH2025
A stored XSS vulnerability in Quantum Manager component 1.0.0-3.2.0 for Joomla was discovered. The SVG upload feature does not sanitize uploads.
CVE-2025-54299CRITICAL2025
A stored XSS vulnerability in No Boss Testimonials component 1.0.0-3.0.0 and 4.0.0-4.0.2 for Joomla was discovered.
CVE-2025-54298CRITICAL2025
A stored XSS vulnerability in CommentBox component 1.0.0-1.1.0 for Joomla was discovered.
CVE-2025-54297HIGH2025
A stored XSS vulnerability in CComment component 5.0.0-6.1.14 for Joomla was discovered.
CVE-2025-54296HIGH2025
A stored XSS vulnerability in ProFiles component 1.0-1.5.0 for Joomla was discovered.
CVE-2025-54295MEDIUM2025
A Reflected XSS vulnerability in DJ-Reviews component 1.0-1.3.6 for Joomla was discovered.
CVE-2025-50126MEDIUM2025
A stored XSS vulnerability in the RSBlog! component 1.11.6-1.14.5 Joomla was discovered. The issue allows remote authenticated users to inject arbitrary web script or HTML via the jform[tags_text] parameter.
CVE-2025-50058MEDIUM2025
A stored XSS vulnerability in the RSDirectory! component 1.0.0-2.2.8 Joomla was discovered. The issue allows remote authenticated attackers to inject arbitrary web script or HTML via the review reply component.
CVE-2025-50056MEDIUM2025
A reflected XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 28 Joomla was discovered. The issue allows remote attackers to inject arbitrary web script or HTML via the crafted parameter.
CVE-2025-49486HIGH2025
A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla allows privileged users to store malicious scripts in gallery items.
CVE-2025-32465HIGH2025
A stored XSS vulnerability in RSTickets! component 1.9.12 - 3.3.0 for Joomla was discovered. It allows attackers to perform cross-site scripting (XSS) attacks via sending crafted payload.
CVE-2025-30084MEDIUM2025
A stored XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 for Joomla was discovered. The issue occurs within the dashboard component, where user-supplied input is not properly sanitized before being stored and rendered. An attacker can inject malicious JavaScript code into text fields or ot…
CVE-2025-27754MEDIUM2025
A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows authenticated users to inject malicious JavaScript into the plugin's resource. The injected payload is stored by the application and later executed when other users view the affected c…
CVE-2025-27444MEDIUM2025
A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered. The issue arises from the improper handling of the filter[dateFrom] GET parameter, which is reflected unescaped in the administrative backend interface. This allows an authenticated attacker with admin or…
CVE-2024-40748HIGH2024
Lack of output escaping in the id attribute of menu lists.
CVE-2024-40747MEDIUM2024
Various module chromes didn't properly process inputs, leading to XSS vectors.
CVE-2024-40746MEDIUM2024
A stored cross-site scripting (XSS) vulnerability in HikaShop Joomla Component < 5.1.1 allows remote attackers to execute arbitrary JavaScript in the web browser of a user, by including a malicious payload in the `description` parameter of any product. The `description `parameter is not sanitised in…
CVE-2024-40745MEDIUM2024
Reflected Cross site scripting vulnerability in Convert Forms component for Joomla in versions before 4.4.8.
CVE-2024-40743MEDIUM2024
The stripImages and stripIframes methods didn't properly process inputs, leading to XSS vectors.
CVE-2024-27186MEDIUM2024
The mail template feature lacks an escaping mechanism, causing XSS vectors in multiple extensions.
CVE-2024-27183MEDIUM2024
XSS vulnerability in DJ-HelpfulArticles component for Joomla.
CVE-2024-26279MEDIUM2024
The wrapper extensions do not correctly validate inputs, leading to XSS vectors.
CVE-2024-26278MEDIUM2024
The Custom Fields component not correctly filter inputs, leading to a XSS vector.
CVE-2024-21731MEDIUM2024
Improper handling of input could lead to an XSS vector in the StringHelper::truncate method.
CVE-2024-21730MEDIUM2024
The fancyselect list field layout does not correctly escape inputs, leading to a self-XSS vector.
CVE-2024-21729MEDIUM2024
Inadequate input validation leads to XSS vulnerabilities in the accessiblemedia field.
CVE-2024-21727MEDIUM2024
XSS vulnerability in DP Calendar component for Joomla.
CVE-2024-21726MEDIUM2024
Inadequate content filtering leads to XSS vulnerabilities in various components.
CVE-2024-21725MEDIUM2024
Inadequate escaping of mail addresses lead to XSS vulnerabilities in various components.
CVE-2024-21724MEDIUM2024
Inadequate input validation for media selection fields lead to XSS vulnerabilities in various extensions.
CVE-2023-54364MEDIUM2023
Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, fro…
CVE-2023-54363MEDIUM2023
Joomla Solidres 2.13.3 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating multiple GET parameters including show, reviews, type_id, distance, facilities, categories, prices, location, and Itemid. Attackers can cra…
CVE-2023-54361MEDIUM2023
Joomla iProperty Real Estate 4.1.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the filter_keyword parameter. Attackers can craft URLs containing JavaScript payloads in the filter_keyword GET parameter of the all-properties…
CVE-2023-54360MEDIUM2023
Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can craft malicious links containing JavaScript payloads that execute in victims' browsers when clicked, enabling …
CVE-2023-40659—2023
A reflected XSS vulnerability was discovered in the Easy Quick Contact module for Joomla.
CVE-2023-40658—2023
A reflected XSS vulnerability was discovered in the Clicky Analytics Dashboard module for Joomla.
CVE-2023-40657—2023
A reflected XSS vulnerability was discovered in the Joomdoc component for Joomla.
CVE-2023-40656—2023
A reflected XSS vulnerability was discovered in the Quickform component for Joomla.
CVE-2023-40655—2023
A reflected XSS vulnerability was discovered in the Proforms Basic component for Joomla.
CVE-2023-40628—2023
A reflected XSS vulnerability was discovered in the Extplorer component for Joomla.
CVE-2023-40627—2023
A reflected XSS vulnerability was discovered in the LivingWord component for Joomla.
CVE-2023-39971—2023
Improper Neutralization of Input During Web Page Generation vulnerability in AcyMailing Enterprise component for Joomla allows XSS. This issue affects AcyMailing Enterprise component for Joomla: 6.7.0-8.6.3.
CVE-2023-38045—2023
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.
CVE-2023-23756—2023
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in advcomsys.com oneVote component for Joomla. It allows XSS Targeting Non-Script Elements.
CVE-2023-23754MEDIUM2023
An issue was discovered in Joomla! 4.2.0 through 4.3.1. Lack of input validation caused an open redirect and XSS issue within the new mfa selection screen.