Joomla 扩展 - joomshaper.com - Helix Ultimate 2.2.10 之前版本中 MegaMenu 布局容器及嵌入式输入字段存在存储型跨站脚本(XSS)漏洞 在 Helix Ultimate 2.2.10 之前版本中,MegaMenu 布局 JSON 中存储的未净化的列和条目配置值在渲染时未进行完整的上下文转义,导致可注入恶意的 HTML/JS 代码。修复措施包括实施更严格的净化处理,并通过 和 引入标签白名单机制。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| joomshaper.com | Helix Ultimate extension for Joomla | 1.0-2.2.9 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-78078 | 8.9 HIGH | Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in |
| CVE-2026-78079 | 5.3 MEDIUM | Joomla Extension - joomshaper.com - Privileged File Upload Bypass via Content Spoofing in |
| CVE-2026-78076 | 5.1 MEDIUM | Joomla Extension - joomshaper.com - Broken Access Control & Missing Authorization in MegaM |
| CVE-2026-78075 | 5.1 MEDIUM | Joomla Extension - joomshaper.com - Broken Object-Level Authorization in Blog Image Deleti |
No comments yet