Joomla VirtueMart Shopping-Cart Reflected Cross-Site Scripting Vulnerability

Vulnerability

A reflected cross-site scripting vulnerability has been identified in Joomla VirtueMart Shopping-Cart version 4.0.12. This vulnerability allows attackers to inject malicious scripts by manipulating the keyword parameter in the product-variants endpoint. Exploitation of this issue could lead to the execution of arbitrary JavaScript in the browsers of victims, potentially allowing attackers to steal session tokens or credentials.

Impact

Exploitation of this vulnerability could result in reflected cross-site scripting, allowing for the execution of malicious scripts in the context of the user's browser.

Reproduction

To reproduce this vulnerability, send a crafted URL that includes a script payload in the keyword parameter of the product-variants endpoint. When the victim clicks the link, the injected script will execute in their browser.

Added: Apr 10, 2026, 1:34 AM
Updated: Apr 10, 2026, 1:34 AM

Vulnerability Rating

Custom Algorithm
spread
3.4
impact
1.7
exploitability
7.7
remediation
0.0
relevance
5.5
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.