CVE-2026-21623: Extension - stackideas.com - Persistent XSS in EasyDiscuss component 1.0.0-5.0.15 for Joomla
Published Jan 16, 2026
·Updated
Lack of input filterung leads to a persistent XSS vulnerability in the forum post handling of the Easy Discuss component for Joomla.
Affected Software
3 affected components
StackIdeas EasyDiscuss>=1.0.0<=5.0.15
Joomla joomla
StackIdeas Easydiscuss Joomla\!>=1.0.0<=5.0.15
Event History
Jan 16, 2026
CVE Published
via MITRE·03:04 PM
Data Sourced
via MITRE·03:04 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21623?
CVE-2026-21623 is classified as a high severity vulnerability due to persistent XSS exploitation potential.
2
How do I fix CVE-2026-21623?
To fix CVE-2026-21623, upgrade the EasyDiscuss component to version 5.0.16 or later where the vulnerability is addressed.
3
Which software is affected by CVE-2026-21623?
CVE-2026-21623 affects EasyDiscuss versions 1.0.0 to 5.0.15 for Joomla.
4
What type of vulnerability is CVE-2026-21623?
CVE-2026-21623 is a persistent cross-site scripting (XSS) vulnerability.
5
How does CVE-2026-21623 impact Joomla users?
CVE-2026-21623 allows attackers to inject malicious scripts into forum posts, potentially compromising user accounts.