J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla Workflow•Vote by 11 October•How to vote
CVE-2025-54297HighCVSS 7.0CVE published 23 July 2025Added to mySites.guru 23 July 2025
CComment (com_comment) 5.0.0 to 6.1.14 - Authenticated Stored XSS
CComment by Compojoom, versions 5.0.0 through 6.1.14, contains a stored cross-site scripting vulnerability. A comment payload is persisted by the component and executed when other users, including administrators moderating comments, view the affected content. Update to 6.1.15 or later.
The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.
Updating for CVE-2025-54297 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.
CVE-2025-54297 affects CComment from 5.0.0 up to and including 6.1.14.
How do I fix CVE-2025-54297?
Update CComment to 6.1.15 or later. Then confirm the installed version on the Joomla administrator's Extensions: Manage screen.
How severe is CVE-2025-54297?
Joomla CNA scores it 7.0 (High) under CVSS 4.0. In plain terms: reachable across the internet, needs an account with elevated rights and someone has to be talked through a few steps.
Running an affected version on a site you manage?
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
We use essential cookies to run the site. With your consent we also use Google Analytics and a Meta pixel to measure and improve our marketing. See our cookie policy.