CyberRota Analysis
AI-GeneratedJoomla! versions 4.0.0 to 5.4.8 and 6.0.0 to 6.1.3 are vulnerable due to improper escaping of user-supplied values in the module list layout, which allows for cross-site scripting (XSS) attacks. This vulnerability could enable attackers to execute malicious scripts in the context of a user's session, potentially compromising sensitive information. Organizations using affected Joomla! versions should prioritize patching to mitigate the risk of exploitation.
Original NVD Description
Joomla! Core - [20260912] - Core - XSS in module list in Joomla 4.0.0-5.4.8, 6.0.0-6.1.3 - The module list layout did not properly escape user supplied values, leading to an XSS vector.
Related CVEs
Other vulnerabilities affecting the same vendor(s)