XSS
3 articles tagged XSS, newest first.
Readers also browse

Three OrdaSoft Joomla Extensions Have Unauthenticated SQL Injections in Their Sort Order
Real Estate Manager, Vehicle Manager and Book Library for Joomla each have an SQL injection needing no login and a reflected XSS. Six CVEs and their fixes.

DPCalendar 10.12.0 fixes an SQL injection and an XSS
Digital Peak fixed a blind SQL injection and a stored XSS in DPCalendar 10.12.0, backported to 8.19.5 for Joomla 3. Both need a logged-in user.

Helix Ultimate 2.2.7 Closes an Unauthenticated Menu Write
Helix Ultimate 2.2.7 fixes CSRF and permission gaps in com_ajax: an unauthenticated menu write leading to stored XSS, a file delete, and an open redirect.