CVE-2026-58077: Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2
Published Jul 15, 2026
·Updated
Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in website takeover under some circumstances.
Affected Software
1 affected component
Joomla 4Analytics<5.0.2
Event History
Jul 15, 2026
CVE Published
via MITRE·09:01 AM
Data Sourced
via MITRE·09:01 AM
DescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-58077?
CVE-2026-58077 is classified as high severity, with a score of 8.7 on the CVSS scale.
2
What type of vulnerability is CVE-2026-58077?
CVE-2026-58077 is an unauthenticated stored cross-site scripting (XSS) vulnerability.
3
How do I fix CVE-2026-58077?
To fix CVE-2026-58077, update the Joomla extension 4Analytics to version 5.0.2 or later.
4
What can attackers achieve with CVE-2026-58077?
Attackers exploiting CVE-2026-58077 may gain the ability to take over websites under certain circumstances.
5
Which software is affected by CVE-2026-58077?
CVE-2026-58077 affects the Joomla extension 4Analytics versions prior to 5.0.2.