CVE-2026-21624: Extension - stackideas.com - Persistent XSS in EasyDiscuss component 1.0.0-5.0.15 for Joomla
Published Jan 16, 2026
·Updated
Lack of input filterung leads to a persistent XSS vulnerability in the user avatar text handling of the Easy Discuss component for Joomla.
Affected Software
2 affected components
StackIdeas EasyDiscuss>=1.0.0<5.0.15
StackIdeas Easydiscuss Joomla\!>=1.0.0<=5.0.15
Event History
Jan 16, 2026
CVE Published
via MITRE·03:05 PM
Data Sourced
via MITRE·03:05 PM
DescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-21624?
CVE-2026-21624 is classified as a high severity vulnerability due to its potential for exploitation via persistent XSS.
2
How do I fix CVE-2026-21624?
To fix CVE-2026-21624, update the EasyDiscuss component to a version later than 5.0.15.
3
What is the impact of CVE-2026-21624?
The impact of CVE-2026-21624 is that it allows attackers to execute arbitrary scripts in the context of a victim's browser.
4
Which versions of EasyDiscuss are affected by CVE-2026-21624?
CVE-2026-21624 affects all versions of EasyDiscuss from 1.0.0 up to and including 5.0.15.
5
Who is the vendor for CVE-2026-21624?
The vendor for CVE-2026-21624 is StackIdeas, the creator of the EasyDiscuss component.