CVE-2017-5673: Kunena
Medium severity, CVSS 6.1. EPSS: 0.7% chance of exploitation in the next 30 days.
In the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum message subject (aka topic subject) accepts JavaScript, leading to XSS. Six files are affected: crypsis/layouts/message/item/default.php, crypsis/layouts/message/item/top/default.php, crypsis/layouts/message/item/bottom/default.php, crypsisb3/layouts/message/item/default.php, crypsisb3/layouts/message/item/top/default.php, and crypsisb3/layouts/message/item/bottom/default.php. This is fixed in 5.0.5.
Affected products
- Kunena Kunena: version 5.0.2 only; version 5.0.3 only; version 5.0.4 only
Published 2017-03-22. Last modified 2026-06-17.