CVE-2026-58148: Chronoengine.com Chronoforms Extension For Joomla

High severity, CVSS 8.7. EPSS: 0.4% chance of exploitation in the next 30 days.

Joomla Extension - chronoengine.com - Stored XSS in ChronoForms extension for Joomla 8.0 - 8.0.52 - The Joomla extension ChronoForms is vulnerable to an unauthenticated stored XSS vulnerability.

Affected products

Published 2026-07-17. Last modified 2026-07-23.