CVE-2026-78302
moderateUnauthenticated Stored XSS in JoomShaper SP Property for Joomla
SP Property, a real-estate listing extension for Joomla by JoomShaper, fails to contextually escape attributes and text values when rendering multiple frontend view templates and administrator list tables, allowing unauthenticated attackers to inject script that later executes in victims' browsers. An attacker submits crafted content that is stored and then rendered directly into HTML without escaping; when a user, including a site administrator reviewing listings in the back end, loads an affected page, the injected JavaScript runs in that user's session. Successful exploitation can lead to cookie/session theft, unauthorized actions performed with the victim's privileges, and potentially broader site compromise if an administrator triggers the payload. Any Joomla installation running SP Property prior to version 4.1.4 is affected. As of now the flaw is not on CISA KEV, and no public proof-of-concept or confirmed in-the-wild exploitation is known.
What to do: Upgrade SP Property to version 4.1.4 or later, which adds contextual escaping in the affected frontend views and administrator list tables. Until upgraded, restrict unauthenticated submission of listing-related data where feasible and review stored listing fields for injected HTML or JavaScript. Administrators should monitor for suspicious sessions or unexpected admin-account changes, since back-end list pages are among the unescaped render paths.
| JoomShaper (joomshaper.com) SP Property (Joomla extension) | all versions prior to 4.1.4 (fixed in 4.1.4) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly into HTML without contextual escaping.
- Ecosystems
- Joomla
- Weakness
- CWE-79
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.