Threat intelligence dashboard
CVE-2026-100753medium

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9

Joomla Extension - ordasoft.com - Reflected Cross-Site Scripting in Real Estate Manager (Free) < 6.7.9 - The public property-detail page’s “leave a review” form repopulates its title field directly from the request with no escaping and no filtering function of any kind, unlike the adjacent comment field on the same form, which at least receives partial tag-stripping. A " character in the title query parameter breaks out of the HTML attribute the value is placed in, allowing a following <script> element to execute in the browser of anyone who loads the crafted link.

Risk score

5.3

CVSS 4.0

Vendor
ordasoft.com
Product
Real Estate Manager (Free) extension for Joomla
CWE
CWE-79
Published
Sep 28, 2026
Updated
Sep 28, 2026
CISA KEV
Not flagged

Affected products and versions

Real Estate Manager (Free) extension for Joomla

ordasoft.com

Version / rangeStatusType
1.0.0-6.7.8affected—

Technical metrics

5.3

CVSS 4.0

Severity
medium
Source
Joomla
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N