Reflected XSS Vulnerability in Joomdle Joomla Extension by Joomdle
CVE-2026-65882

Currently unrated

Key Information:

Vendor
CVE Published:
28 July 2026

What is CVE-2026-65882?

A reflected cross-site scripting (XSS) vulnerability has been identified in the Joomdle extension for Joomla. The flaw resides in the 'goto' URL parameter within the Moodle wrapper endpoint, allowing an attacker to inject malicious scripts. This could enable an attacker to execute harmful JavaScript in the context of the user's browser, potentially leading to unauthorized access to sensitive data or further exploitation of the affected site.

Affected Version(s)

Joomdle component for Joomla 0.7.0-3.0.1

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Krzysztof ZajÄ…c, CERT PL
.