AUGUST 25, 2026
Live Feed
Back to database
Case File

CVE-2026-48952

MEDIUM · CVSS 6.1 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-07 · Last synced 2026-08-06

CyberRota Analysis

AI-Generated

The vulnerability arises from inadequate input escaping in the update list view of the com_installer component, allowing for potential cross-site scripting (XSS) attacks. This could enable attackers to execute arbitrary scripts in the context of a user's session, potentially compromising sensitive information. Organizations utilizing this component should prioritize remediation to mitigate the risk of exploitation.

CVE
CVE-2026-48952
Severity
MEDIUM
CVSS
6.1
EPSS
0.15%

Original NVD Description

Lack of escaping leads to an XSS vulnerability in the update list view of com_installer.

Related CVEs

Other vulnerabilities affecting the same vendor(s)