Junglewise Threat Intelligence

CVE-2026-77027: Fabrik unauthenticated stored XSS in jsactions feature

CVE-2026-77027 · Severity: info · CVSS 7.1 · Published 2026-08-22

Technologies: Fabrik. Vendors: Fabrik.

Executive brief

Fabrik is a popular Joomla extension for building custom web applications and forms without requiring programming knowledge. An unauthenticated attacker can inject malicious JavaScript code through the jsactions feature that persists in the application, allowing them to steal user credentials, perform unauthorized actions on behalf of logged-in users, or deface the application interface.

Technical details

This is a stored cross-site scripting (XSS) vulnerability in Fabrik versions prior to 4.7.2, caused by inadequate input validation in the jsactions feature. The vulnerability allows unauthenticated attackers to inject arbitrary HTML and JavaScript code that is stored server-side and executed in the browsers of other users who view the affected content. No authentication is required to exploit this vulnerability, making it accessible to any network-connected attacker. The injected script executes in the context of the victim's session, potentially allowing cookie theft, session hijacking, or malicious form submission. A patch is available in Fabrik version 4.7.2 and later.

Affected products

  • Fabrik Fabrik < 4.7.2

Timeline

  • 2026-08-22: disclosed

References

Related threats