Junglewise Threat Intelligence

CVE-2026-58148: ChronoEngine ChronoForms stored XSS in Joomla extension

CVE-2026-58148 · Severity: info · CVSS 8.7 · Published 2026-07-17

Executive brief

ChronoForms, a popular form-building tool for Joomla websites, contains a security vulnerability that allows unauthorized individuals to inject malicious scripts into the site. Because this is a "stored" vulnerability, the malicious code remains on the server and can automatically target any administrator or visitor who views the affected form data. This could lead to unauthorized access to user accounts, theft of sensitive session information, or the defacement of the website.

Technical details

A stored Cross-Site Scripting (XSS) vulnerability exists in the ChronoForms extension for Joomla (versions 1.0 through 8.0.52). The flaw stems from improper neutralization of user-supplied input during web page generation (CWE-79). An unauthenticated remote attacker can exploit this by submitting a form containing malicious JavaScript, which is then stored on the server. When a privileged user (such as a site administrator) views the submitted data in the backend, the script executes in their browser context. This can result in full session hijacking, administrative account takeover, or unauthorized modification of site content.

Affected products

  • chronoengine.com ChronoForms extension for Joomla 1.0-8.0.52

Timeline

  • 2026-07-17: disclosed: Initial publication of the CVE record
  • 2026-07-17: advisory: Advisory published by the Joomla! Project

References