---
id: CVE-2023-54364
title: >-
  Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability
  that allows unauthenticated attackers to inject malicious scripts by
  manipulating GET parameters in the product filter endpoint
summary: >-
  Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability
  that allows unauthenticated attackers to inject malicious scripts by
  manipulating GET parameters in the product filter endpoint. Attackers can
  craft malicious …
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'
cwe:
  - CWE-79
published: '2026-04-09'
updated: '2026-09-26'
sourceUpdated: '2026-09-26T23:10:00.127'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-54364'
references:
  - url: 'https://demo.hikashop.com/index.php/en/'
    label: disclosure@vulncheck.com
  - url: 'https://www.exploit-db.com/exploits/51629'
    label: disclosure@vulncheck.com
  - url: 'https://www.hikashop.com/'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/joomla-hikashop-reflected-xss-via-product-filter
    label: disclosure@vulncheck.com
tags:
  - nvd
epss: 0.00226
epssPercentile: 0.12035
ingestedAt: '2026-09-26T23:39:28.807Z'
---

## Overview

Joomla HikaShop 4.7.4 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating GET parameters in the product filter endpoint. Attackers can craft malicious URLs containing XSS payloads in the from_option, from_ctrl, from_task, or from_itemid parameters to steal session tokens or login credentials when victims visit the link.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
