Impact
The Canonical Representation of the vulnerability is a stored cross‑site scripting flaw (CWE‑79) that allows an attacker to embed and persist malicious script code within the ChronoForms extension. When an unauthenticated user submits data containing a script, the form content is stored without proper encoding and later rendered to all visitors of the affected page. This results in arbitrary client‑side code execution.
Affected Systems
The vulnerability affects the ChronoForms extension developed by chronoengine.com, version 8.0 through 8.0.52 on Joomla installations.
Risk and Exploitability
The CVSS base score of 8.7 indicates high severity, while the EPSS score of less than 1% suggests a very low likelihood of exploitation at present. The flaw is not listed in the CISA KEV catalog. Exploitation requires no special privileges and can be performed by any outsider who submits a malicious form entry that is subsequently rendered to site visitors.
OpenCVE Enrichment