CVE-2026-58148: Chronoengine.com Chronoforms Extension For Joomla
High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.
Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability.
Affected products
- Chronoengine.com Chronoforms Extension For Joomla: version 8.0-8.0.52 only
Published 2026-07-17. Last modified 2026-07-23.