Junglewise Threat Intelligence

CVE-2026-57833: weeblr.com 4Analytics stored XSS in AI analysis feature

CVE-2026-57833 · Severity: info · CVSS 8.6 · Published 2026-07-15

Executive brief

4Analytics is a Joomla extension used for private website traffic analysis and AI-driven reporting. A security vulnerability allows unauthenticated attackers to inject malicious scripts into the AI analysis feature. If an administrator views these reports, the scripts could execute, potentially leading to unauthorized access to the website management console or theft of sensitive administrative data.

Technical details

The 4Analytics extension for Joomla (versions 1.0 through 5.0.1) contains a stored Cross-Site Scripting (XSS) vulnerability (CWE-79). The flaw exists in the AI analysis component, where input is improperly neutralized before being rendered in the Joomla administrative interface or emailed reports. An unauthenticated remote attacker can exploit this by submitting malicious data that the AI processes, which then executes in the context of a logged-in administrator's session. This can lead to full administrative compromise. The vulnerability is addressed in versions following 5.0.1.

Affected products

  • weeblr.com 4Analytics extension for Joomla 1.0-5.0.1

Timeline

  • 2026-07-15: disclosed: CVE-2026-57833 published

References

Related threats