Impact
The vulnerability is a stored cross‑site scripting flaw in the SP Property extension for Joomla, affecting all versions prior to 4.1.4. Multiple template files in both the frontend and administration interface render user‑supplied values directly into HTML without contextual escaping. As a result, an unauthenticated attacker could inject arbitrary JavaScript that will persist across page loads and be executed in the browsers of anyone visiting the affected views or admin lists. The flaw can lead to theft of session cookies, account takeover, defacement, or the delivery of malware to site visitors.
Affected Systems
Users running Joomla sites that have installed the joomshaper.com SP Property extension version lower than 4.1.4 are impacted. The extension is widely used for property listings and can appear in front‑end property detail pages and admin list views.
Risk and Exploitability
The CVSS base score of 8.6 indicates high severity, with a risk of exploitation even though the EPSS score is not available. The vulnerability is unauthenticated, so no login is required, and any visitor to the affected pages can trigger the payload. Because the payload is stored, repeated visits can magnify impact. The flaw is not currently listed in CISA’s Known Exploited Vulnerabilities catalog, but its high severity and the lack of authentication requirement make it a priority for immediate patching.
OpenCVE Enrichment