Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index
CVE-2026-78073MediumPublished 28 August 2026

All Video Share (com_allvideoshare) below 4.5.0 - Unauthenticated Reflected Cross-Site Scripting

All Video Share fails to escape a number of user supplied inputs, giving reflected cross-site scripting vectors that need no authentication (CVSS 4.0 vector PR:N, UI:P - the victim must follow a crafted link). Reported by Krzysztof Zajac of CERT PL. NOTE ON THE AFFECTED RANGE: the CVE record contradicts itself. Its structured affected-version field states 1.0.0 to 4.4.99, meaning the flaw is fixed in 4.5.0, while its own title and description both state the range as 1.0.0 to 4.5.0, which would make 4.5.0 affected as well. This rule follows the structured field, so 4.5.0 is treated as fixed. The record also names the vendor inconsistently, as j2commerce.com in the title and mrvinoth.com in the affected block; every installation seen on the platform is Vinoth Kumar / MrVinoth. The CVE gives one continuous affected range from 1.0.0 and no backport to the older 2.x or 3.x lines has been published, so sites still on those lines have no fixed release on their own branch and must move to 4.5.0 or later.

Affected versions: ≥ 1.0.0 and < 4.5.0

Official record: cve.org · NVD

Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.

Affected extensions and versions

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 13 September 2026.