CVE-2025-50056: Extension - rsjoomla.com - Reflected XSS vulnerability RSMail! component 1.19.20-1.22.28 for Joomla
Published Jul 18, 2025
·Updated
A reflected XSS vulnerability in RSMail! component 1.19.20 - 1.22.26 28 Joomla was discovered. The issue allows remote attackers to inject arbitrary web script or HTML via the crafted parameter.
Affected Software
1 affected component
rsjoomla RSMail!>=1.19.20<=1.22.28
Event History
Jul 18, 2025
CVE Published
via MITRE·09:51 AM
Data Sourced
via MITRE·09:51 AM
DescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-50056?
CVE-2025-50056 has a medium severity rating due to its potential to allow remote attackers to execute arbitrary scripts.
2
How do I fix CVE-2025-50056?
To fix CVE-2025-50056, upgrade the RSMail! component to version 1.22.28 or later.
3
What impact does CVE-2025-50056 have on my Joomla site?
CVE-2025-50056 can lead to reflected XSS attacks, allowing attackers to inject malicious scripts into your Joomla site.
4
Which versions of RSMail! are affected by CVE-2025-50056?
CVE-2025-50056 affects RSMail! versions 1.19.20 to 1.22.26.
5
Is CVE-2025-50056 easily exploitable?
Yes, CVE-2025-50056 is easily exploitable as it requires only a crafted parameter to trigger the XSS vulnerability.