Executive brief
4Analytics is a privacy-focused analytics extension for the Joomla content management system that tracks website traffic without using cookies. A security vulnerability in this extension allows an unauthenticated attacker to inject malicious scripts into the website. If successful, this could allow the attacker to take full control of the website, potentially leading to data theft or unauthorized site modifications.
Technical details
The 4Analytics extension for Joomla (versions 1.0 through 5.0.1) contains a stored Cross-Site Scripting (XSS) vulnerability. The flaw resides in the improper neutralization of input during web page generation (CWE-79). An unauthenticated remote attacker can send a specially crafted request containing malicious scripts that are subsequently stored by the extension. When an administrative user views the analytics data, the script executes in their browser context, potentially allowing for session hijacking or full website takeover. The vulnerability is rated High (CVSS 8.7) due to the potential for complete loss of confidentiality, integrity, and availability.
Affected products
- weeblr.com 4Analytics extension for Joomla 1.0-5.0.1
Timeline
- 2026-07-15: advisory: CVE published by Joomla! Project