CVE-2026-63264
Deferred Deferred - Pending Action

Reflected Cross-Site Scripting in JoomShopping Extension

Vulnerability report for CVE-2026-63264, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-23

Assigner: Joomla! Project

Description

Joomla Extension - joomshopping.com - Reflective XSS in JoomShopping < 5.9.3 - The Joomla extension JoomShopping is vulnerable to an reflected XSS vulnerability in the product frontend controller.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-23
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-10
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
maxxmarketing joomshopping *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The Joomla extension JoomShopping has a reflected cross-site scripting (XSS) vulnerability in its product frontend controller. This means an attacker can inject malicious scripts into web pages viewed by users, which execute in the context of the user's browser.

Detection Guidance

To detect this reflected XSS vulnerability in JoomShopping versions below 5.9.3, inspect web traffic for suspicious input parameters in the product frontend controller. Check for unusual JavaScript execution in browser consoles when accessing product pages. Review server logs for requests containing XSS payloads like <script>alert(1)</script> in URL parameters.

Impact Analysis

An attacker could steal user sessions, redirect users to malicious sites, or perform actions on behalf of users. This could lead to unauthorized access to sensitive data or account compromise if users interact with the crafted link.

Compliance Impact

The reflected XSS vulnerability in JoomShopping could potentially expose user data, which may impact compliance with GDPR if personal data is compromised. However, the provided context does not specify data handling or security measures, so the exact impact on GDPR or HIPAA compliance cannot be determined.

Mitigation Strategies

Update JoomShopping to the latest patched version immediately. Disable the product frontend controller if not in use. Monitor network traffic for suspicious XSS attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-63264. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart