Stored XSS Vulnerability in RSBlog! Component for Joomla
CVE-2025-27754
6.5MEDIUM
What is CVE-2025-27754?
A stored Cross-Site Scripting (XSS) vulnerability exists in the RSBlog! component for Joomla, affecting versions 1.11.6 to 1.14.4. This vulnerability enables authenticated users to inject malicious JavaScript code into the plugin's resources. The malicious payload is then stored by the application and executed when other users access the compromised content, potentially leading to unauthorized actions or data exposure.
Affected Version(s)
RSBlog component for Joomla 1.11.6-1.14.4