{"id":"CVE-2026-77027","title":"Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector.","summary":"Joomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector.","severity":"none","cwe":["CWE-79"],"published":"2026-08-22","updated":"2026-08-22","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-77027","references":[{"url":"https://www.fabrikar.com/","label":"security@joomla.org"}],"tags":["nvd"],"ingestedAt":"2026-08-23T06:43:33.400Z","epss":0.00258,"epssPercentile":0.17757,"slug":"CVE-2026-77027","body":"## Overview\n\nJoomla Extension - fabrikar.com - Unauthenticated stored XSS in Fabrik < 4.7.2 - The handling of user supplied input in the jsactions feature leads to an stored XSS vector.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}