Medium severityNVD Advisory· Published Sep 28, 2026
CVE-2026-100753
CVE-2026-100753
Description
Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment field on the same form, which at least receives partial tag-stripping. A " character in the title query parameter breaks out of the HTML attribute the value is placed in, allowing a following element to execute in the browser of anyone who loads the crafted link.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <6.7.9
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.