CVE-2026-77027: Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2
Published Aug 22, 2026
·Updated
Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector.
Affected Software
1 affected component
fabrikar.com<4.7.2
Event History
Aug 22, 2026
CVE Published
via MITRE·02:21 PM
Data Sourced
via MITRE·02:21 PM
DescriptionWeakness
Data Sourced
via NVD·03:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which deployments are affected?
Fabrik versions earlier than 4.7.2 are affected. The available information does not identify any configuration prerequisite for the vulnerable jsactions feature.
2
Does exploitation require an authenticated Joomla account?
No. The issue is described as unauthenticated stored XSS, so an attacker does not need to authenticate before submitting the malicious input.
3
What is the available remediation?
Upgrade Fabrik to version 4.7.2 or later. No alternative mitigation is provided in the available information.