SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-58148

HIGH · CVSS 8.7 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The ChronoForms extension for Joomla versions 8.0 to 8.0.52 is susceptible to an unauthenticated stored cross-site scripting (XSS) vulnerability, allowing attackers to inject malicious scripts that can execute in the context of users accessing the affected site. This could lead to data theft, session hijacking, or defacement of the website. Joomla site administrators using this extension should prioritize patching or mitigating this vulnerability to protect their users and data integrity.

CVE
CVE-2026-58148
Severity
HIGH
CVSS
8.7
EPSS
0.32%

Original NVD Description

Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability.