CVE-2026-78302: Joomla Extension - joomshaper.com - Unauthenticated Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4
Published Sep 10, 2026
·Updated
Joomla Extension - joomshaper.com - Unauthenticated Stored Cross-Site Scripting (XSS) via Unescaped Output in Views and Admin Lists in SP Property < 4.1.4 - Multiple template files across frontend views and administrator list tables rendered attributes and text values directly into HTML without contextual escaping.
Affected Software
1 affected component
joomshaper.com Joomla Extension (SP Property)<4.1.4
Event History
Sep 10, 2026
CVE Published
via MITRE·10:02 AM
Data Sourced
via MITRE·10:02 AM
DescriptionWeakness
Frequently Asked Questions
1
Which releases need to be reviewed?
The affected range is SP Property versions earlier than 4.1.4.
2
Where can unescaped content be rendered?
The issue affects multiple template files used by frontend views and administrator list tables, where attribute and text values were inserted into HTML without contextual escaping.
3
Does exploitation require authentication?
The vulnerability is described as unauthenticated stored XSS, so authentication is not required for the attacker.