CVE-2025-27754: Rsjoomla Rsform!blog

Medium severity, CVSS 6.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A stored XSS vulnerability in RSBlog! component 1.11.6 - 1.14.4 for Joomla was discovered. The vulnerability allows authenticated users to inject malicious JavaScript into the plugin's resource. The injected payload is stored by the application and later executed when other users view the affected content.

Affected products

  • Rsjoomla Rsform!blog: from 1.11.6, up to and including 1.14.4

Published 2025-06-05. Last modified 2026-06-17.