Description
Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in website takeover under some circumstances.
Published: 2026-07-15
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The weeblr.com 4Analytics extension for Joomla has an unauthenticated stored cross‑site scripting flaw that stems from an uncontrolled input field. The attacker can submit a crafted request that stores malicious JavaScript, which is later rendered to visitors without proper escaping. According to the updated description, the flaw may lead to website takeover in certain circumstances, allowing the attacker to hijack user sessions, deface the site, or execute arbitrary code in the context of the website.

Affected Systems

The vulnerability affects the weeblr.com 4Analytics extension for Joomla versions earlier than 5.0.2. All installations running those versions are impacted, regardless of site size or traffic.

Risk and Exploitability

With a CVSS score of 8.7 the flaw is considered high severity, but the EPSS score of less than 1% indicates a low current exploitation probability. The flaw is not listed in CISA's KEV catalog. Attackers can exploit it by sending a crafted, unauthenticated request that stores malicious payloads in the extension, which are then executed when the site is accessed by any user.

Generated by OpenCVE AI on August 3, 2026 at 03:05 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the vendor's website or contact the vendor for information about a patch or mitigation.
  • If an immediate upgrade is not possible, temporarily disable the extension or limit its visibility to authenticated users only.
  • Scan payloads and remove or sanitize any malicious entries to prevent already‑stored attacks.

Generated by OpenCVE AI on August 3, 2026 at 03:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Weeblr.com
Weeblr.com 4analytics Extension For Joomla
Vendors & Products Weeblr.com
Weeblr.com 4analytics Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in website takeover under some circumstances. Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2 - The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in website takeover under some circumstances.

Wed, 15 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 15 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description The Joomla extension 4Analytics is vulnerable to an unauthenticated stored XSS. A specially crafted unauthenticated request may result in website takeover under some circumstances.
Title Joomla Extension - weeblr.com - Unauthenticated stored XSS in 4Analytics < 5.0.2
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Weeblr.com 4analytics Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T15:00:14.727Z

Reserved: 2026-06-28T18:39:37.301Z

Link: CVE-2026-58077

cve-icon Vulnrichment

Updated: 2026-07-15T12:27:41.128Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T03:15:05Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')