A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows authenticated users to inject malicious JavaScript into the plugin's resource. The injected payload is stored by the application and later executed when other users view the affected content.
References
Link Providers
https://rsjoomla.com/ cve-icon cve-icon
History

Mon, 16 Jun 2025 17:45:00 +0000

Type Values Removed Values Added
First Time appeared Rsjoomla
Rsjoomla rsform\!blog
CPEs cpe:2.3:a:rsjoomla:rsform\!blog:*:*:*:*:*:joomla\!:*:*
Vendors & Products Rsjoomla
Rsjoomla rsform\!blog

Thu, 05 Jun 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:L/I:L/A:L'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 05 Jun 2025 13:30:00 +0000

Type Values Removed Values Added
Description A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows authenticated users to inject malicious JavaScript into the plugin's resource. The injected payload is stored by the application and later executed when other users view the affected content.
Title Extension - rsjoomla.com - A stored XSS vulnerability RSBlog! component 1.11.6 - 1.14.4 for Joomla
Weaknesses CWE-79
References

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published: 2025-06-05T13:20:52.604Z

Updated: 2025-06-08T04:39:04.489Z

Reserved: 2025-03-06T04:34:05.523Z

Link: CVE-2025-27754

cve-icon Vulnrichment

Updated: 2025-06-05T13:44:30.500Z

cve-icon NVD

Status : Analyzed

Published: 2025-06-05T14:15:31.683

Modified: 2025-06-16T17:28:53.470

Link: CVE-2025-27754

cve-icon Redhat

No data.