CVE-2026-100753
Received Received - Intake

Reflected XSS in Joomla Real Estate Manager Extension

Vulnerability report for CVE-2026-100753, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: Joomla! Project

Description

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment field on the same form, which at least receives partial tag-stripping. A " character in the title query parameter breaks out of the HTML attribute the value is placed in, allowing a following <script> element to execute in the browser of anyone who loads the crafted link.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
ordasoft real_estate_manager to 6.7.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a reflected Cross-Site Scripting (XSS) vulnerability in the Real Estate Manager Joomla extension versions below 6.7.9. The issue occurs on the public property-detail page where the 'leave a review' form's title field is populated directly from user input without proper sanitization. This allows attackers to inject malicious scripts via crafted URLs that execute in the browsers of users who click the link.

Detection Guidance

To detect this reflected XSS vulnerability in Joomla's Real Estate Manager, inspect web server access logs for unusual query parameters in the property-detail page URL, particularly the 'title' parameter containing script tags or quotes. Check if the 'title' field in review forms is reflected without proper escaping.

Impact Analysis

An attacker could trick you into clicking a specially crafted link that executes malicious JavaScript in your browser. This could lead to session hijacking, stealing cookies, redirecting you to phishing sites, or performing actions on your behalf without your knowledge. It primarily affects users who interact with the vulnerable Joomla site.

Compliance Impact

This XSS vulnerability could lead to unauthorized data access or modification, potentially violating GDPR's integrity and confidentiality requirements or HIPAA's safeguards for protected health information. Organizations may face compliance violations if user data is compromised through such attacks.

Mitigation Strategies

Immediately update the Real Estate Manager extension to version 6.7.9 or later. If an update is unavailable, disable the extension temporarily. Implement input validation and output encoding for the 'title' parameter in the review form to strip or escape HTML tags.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100753. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart