CVE-2026-58148: Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52
Published Jul 17, 2026
·Updated
Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability.
Affected Software
1 affected component
Joomla ChronoForms>=8.0<=8.0.52
Event History
Jul 17, 2026
CVE Published
via MITRE·03:48 PM
Data Sourced
via MITRE·03:48 PM
DescriptionWeakness
Data Sourced
via NVD·04:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-58148?
CVE-2026-58148 has a high severity rating of 8.7.
2
How do I fix CVE-2026-58148?
To fix CVE-2026-58148, update the ChronoForms extension to version 8.0.53 or later.
3
What type of vulnerability is CVE-2026-58148?
CVE-2026-58148 is categorized as a stored Cross-Site Scripting (XSS) vulnerability.
4
Who is affected by CVE-2026-58148?
CVE-2026-58148 affects all users of the ChronoForms Joomla extension prior to version 8.0.53.
5
Is CVE-2026-58148 exploitable remotely?
Yes, CVE-2026-58148 is exploitable remotely without authentication.