ZeroHour

CVE-2026-78302

moderate

Unauthenticated Stored XSS in JoomShaper SP Property for Joomla

CVSS 4.0
8.6 high
EPSS
Published
()
Modified
AI analysis

SP Property, a real-estate listing extension for Joomla by JoomShaper, fails to contextually escape attributes and text values when rendering multiple frontend view templates and administrator list tables, allowing unauthenticated attackers to inject script that later executes in victims' browsers. An attacker submits crafted content that is stored and then rendered directly into HTML without escaping; when a user, including a site administrator reviewing listings in the back end, loads an affected page, the injected JavaScript runs in that user's session. Successful exploitation can lead to cookie/session theft, unauthorized actions performed with the victim's privileges, and potentially broader site compromise if an administrator triggers the payload. Any Joomla installation running SP Property prior to version 4.1.4 is affected. As of now the flaw is not on CISA KEV, and no public proof-of-concept or confirmed in-the-wild exploitation is known.

What to do: Upgrade SP Property to version 4.1.4 or later, which adds contextual escaping in the affected frontend views and administrator list tables. Until upgraded, restrict unauthenticated submission of listing-related data where feasible and review stored listing fields for injected HTML or JavaScript. Administrators should monitor for suspicious sessions or unexpected admin-account changes, since back-end list pages are among the unescaped render paths.

Affected
JoomShaper (joomshaper.com) SP Property (Joomla extension)all versions prior to 4.1.4 (fixed in 4.1.4)
Estimated exposure
moderatelikely thousands of Joomla sites, plausibly up to low tens of thousands; no public install count is available — No active-install metrics were provided, so this is an estimate: SP Property is a commercial real-estate component for Joomla, a niche vertical within the CMS's multi-million-site base, making deployments plausibly in the thousands to low…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly into HTML without contextual escaping.

Ecosystems
Joomla
Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.