Home

Description

A unauthenticated reflected XSS vulnerability in VirtueMart 1.0.0-4.4.10 for Joomla was discovered.

PUBLISHED Reserved 2025-08-16 | Published 2025-10-25 | Updated 2025-10-28 | Assigner Joomla

Problem types

CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

Product status

Default status
unaffected

1.0.0-4.4.10
affected

Credits

Adam Wallwork finder

References

virtuemart.net/ product

github.com/AdamWallwork/CVEs/tree/main/2025/CVE-2025-55757 third-party-advisory

cve.org (CVE-2025-55757)

nvd.nist.gov (CVE-2025-55757)

Download JSON