What is CVE-2026-63264?
This CVE describes a Reflected XSS vulnerability in the product frontend controller of the JoomShopping extension for Joomla, affecting versions below 5.9.3. Exploitation could allow an attacker to execute malicious scripts in a user's browser. Updating the extension to version 5.9.3 or later is recommended.
Azərbaycanca: Bu CVE, Joomla-nın JoomShopping genişlənməsinin 5.9.3-dən əvvəlki versiyalarında məhsul frontend kontrollerində aşkarlanmış Reflected XSS zəifliyini təsvir edir. İstismar zamanı təcavüzkar istifadəçi brauzerində zərərli skript icra etdirə bilər. Genişlənməni ən az 5.9.3 versiyasına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79; shared vendor: Joomla
FAQ2
What platform and extension are affected by CVE-2026-63264?
This vulnerability affects the JoomShopping extension for Joomla in versions prior to 5.9.3.
How can the Reflected XSS vulnerability in CVE-2026-63264 be addressed?
It is recommended to update the JoomShopping extension to version 5.9.3 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.