Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, from_task, or from_itemid parameters to steal session tokens or login credentials when victims visit the link.
Metrics
Affected Vendors & Products
References
History
Fri, 10 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 09 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, from_task, or from_itemid parameters to steal session tokens or login credentials when victims visit the link. | |
| Title | Joomla HikaShop 4.7.4 Reflected XSS via Product Filter | |
| First Time appeared |
Hikashop
Hikashop hikashop |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:hikashop:hikashop:4.7.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Hikashop
Hikashop hikashop |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-04-09T20:54:53.568Z
Updated: 2026-04-10T18:10:51.242Z
Reserved: 2026-04-09T20:42:23.652Z
Link: CVE-2023-54364
Updated: 2026-04-10T18:10:46.242Z
Status : Awaiting Analysis
Published: 2026-04-09T21:16:06.117
Modified: 2026-04-13T15:02:27.760
Link: CVE-2023-54364
No data.