diff --git a/advisories/unreviewed/2026/04/GHSA-24p2-2h4q-gmhf/GHSA-24p2-2h4q-gmhf.json b/advisories/unreviewed/2026/04/GHSA-24p2-2h4q-gmhf/GHSA-24p2-2h4q-gmhf.json index 73c8962bc33a8..1d3280fef16ca 100644 --- a/advisories/unreviewed/2026/04/GHSA-24p2-2h4q-gmhf/GHSA-24p2-2h4q-gmhf.json +++ b/advisories/unreviewed/2026/04/GHSA-24p2-2h4q-gmhf/GHSA-24p2-2h4q-gmhf.json @@ -1,23 +1,37 @@ { "schema_version": "1.4.0", "id": "GHSA-24p2-2h4q-gmhf", - "modified": "2026-04-09T21:31:25Z", + "modified": "2026-04-09T21:32:32Z", "published": "2026-04-01T12:31:28Z", "aliases": [ "CVE-2026-21631" ], + "summary": "XSS vector in com_associations comparison view", "details": "Lack of output escaping leads to a XSS vector in the multilingual associations component.", "severity": [ { "type": "CVSS_V3", "score": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N" - }, + } + ], + "affected": [ { - "type": "CVSS_V4", - "score": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:U/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" + "package": { + "ecosystem": "npm", + "name": "" + }, + "ranges": [ + { + "type": "ECOSYSTEM", + "events": [ + { + "introduced": "0" + } + ] + } + ] } ], - "affected": [], "references": [ { "type": "ADVISORY", @@ -30,6 +44,10 @@ { "type": "WEB", "url": "https://github.com/Shirshaw64p/security-advisories/tree/main/CVE-2026-21631" + }, + { + "type": "PACKAGE", + "url": "joomla/joomla-cms" } ], "database_specific": {