Junglewise Threat Intelligence

CVE-2026-78073: Joomla All Video Share reflected XSS in user inputs

CVE-2026-78073 · Severity: info · CVSS 6.1 · Published 2026-08-28

Executive brief

All Video Share is a popular Joomla extension for publishing and managing video galleries on websites. Multiple user input fields in the extension fail to properly escape data, allowing attackers to inject malicious scripts that execute in visitors' browsers. An attacker can exploit this by crafting a malicious URL that tricks users into clicking it, potentially stealing session cookies, credentials, or performing unauthorized actions on behalf of victims.

Technical details

The vulnerability is a reflected cross-site scripting (XSS) flaw where various user-supplied input parameters are rendered in HTTP responses without proper HTML escaping or output encoding. This allows an attacker to inject arbitrary JavaScript that executes in the context of a victim's browser session. The vulnerability affects All Video Share versions 1.0.0 through 4.5.0 and requires a victim to click a crafted link or visit a malicious page; no authentication is required. An attacker can steal session tokens, perform actions as the victim, or redirect users to phishing sites. The vendor should implement proper input validation and output encoding on all user-supplied parameters.

Affected products

  • mrvinoth.com All Video Share 1.0.0-4.5.0

Timeline

  • 2026-08-28: disclosed: Published to NVD

References