CVE-2025-49486: Extension - balbooa.com - Stored XSS in Balbooa Gallery component version 1.0.0 - 2.4.0 for Joomla
Published Jul 18, 2025
·Updated
A stored XSS vulnerability in the Balbooa Gallery plugin 1.0.0-2.4.0 for Joomla allows privileged users to store malicious scripts in gallery items.
Affected Software
1 affected component
Balbooa Gallery>=1.0.0<=2.4.0
Event History
Jul 18, 2025
CVE Published
via MITRE·09:50 AM
Data Sourced
via MITRE·09:50 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-49486?
CVE-2025-49486 is a high-severity stored XSS vulnerability allowing malicious script storage in gallery items.
2
How do I fix CVE-2025-49486?
To fix CVE-2025-49486, update the Balbooa Gallery plugin to version 2.4.1 or higher.
3
Who is affected by CVE-2025-49486?
The CVE-2025-49486 vulnerability affects privileged users of the Balbooa Gallery plugin from versions 1.0.0 to 2.4.0.
4
What are the implications of CVE-2025-49486?
CVE-2025-49486 allows attackers to execute malicious scripts if exploited, potentially compromising user data.
5
Is CVE-2025-49486 widely exploited?
As of now, there are no reports of active exploitation of CVE-2025-49486, but it poses a significant risk if not addressed.