CVE-2023-54360: Jlexart Joomla Jlex Review
Medium severity, CVSS 6.1. EPSS: 0.2% chance of exploitation in the next 30 days.
Joomla JLex Review 6.0.1 contains a reflected cross-site scripting vulnerability that allows attackers to inject malicious scripts by manipulating the review_id URL parameter. Attackers can craft malicious links containing JavaScript payloads that execute in victims' browsers when clicked, enabling session hijacking or credential theft.
Affected products
- Jlexart Joomla Jlex Review: version 6.0.1 only
Published 2026-04-09. Last modified 2026-09-26.