Stored XSS Vulnerability in RSBlog! Component for Joomla
CVE-2025-27754

6.5MEDIUM

Key Information:

Vendor
CVE Published:
5 June 2025

What is CVE-2025-27754?

A stored Cross-Site Scripting (XSS) vulnerability exists in the RSBlog! component for Joomla, affecting versions 1.11.6 to 1.14.4. This vulnerability enables authenticated users to inject malicious JavaScript code into the plugin's resources. The malicious payload is then stored by the application and executed when other users access the compromised content, potentially leading to unauthorized actions or data exposure.

Affected Version(s)

RSBlog component for Joomla 1.11.6-1.14.4

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kamil Szczurowski
Robert Kruczek
.
CVE-2025-27754 : Stored XSS Vulnerability in RSBlog! Component for Joomla