Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, from_task, or from_itemid parameters to steal session tokens or login credentials when victims visit the link.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 09 Apr 2026 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, from_task, or from_itemid parameters to steal session tokens or login credentials when victims visit the link. | |
| Title | Joomla HikaShop 4.7.4 Reflected XSS via Product Filter | |
| First Time appeared |
Hikashop
Hikashop hikashop |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:hikashop:hikashop:4.7.4:*:*:*:*:*:*:* | |
| Vendors & Products |
Hikashop
Hikashop hikashop |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-04-09T20:55:49.926Z
Reserved: 2026-04-09T20:42:23.652Z
Link: CVE-2023-54364
No data.
Status : Received
Published: 2026-04-09T21:16:06.117
Modified: 2026-04-09T21:16:06.117
Link: CVE-2023-54364
No data.
OpenCVE Enrichment
No data.
Weaknesses