PT-2025-30570 · Unknown · Joomla Ccomment

Sebastian Jeż

·

Published

2025-07-23

·

Updated

2025-07-23

·

CVE-2025-54297

CVSS v4.0

7.0

High

VectorAV:N/AC:H/AT:N/PR:H/UI:A/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Joomla CComment component versions 5.0.0 through 6.1.14
Description A stored cross-site scripting (XSS) issue exists in the CComment component. This allows an attacker to inject malicious scripts into the application, potentially compromising user accounts or website data.
Recommendations Update the CComment component to a version later than 6.1.14.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-54297

Affected Products

Joomla Ccomment