Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-27444


A reflected XSS vulnerability in RSform!Pro component 3.0.0 - 3.3.13 for Joomla was discovered. The issue arises from the improper handling of the filter[dateFrom] GET parameter, which is reflected unescaped in the administrative backend interface. This allows an authenticated attacker with admin or editor privileges to inject arbitrary JavaScript code by crafting a malicious URL.


Published

2025-06-04T08:15:21.613

Last Modified

2025-06-09T15:04:33.780

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 4.8 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-79

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rsjoomla rsform\!pro ≤ 3.3.13 Yes

References