MEDIUM
Hikashop
CVE published 2026-04-09
CVE-2023-54364
CVE-2023-54364 is a reflected cross-site scripting vulnerability in Joomla HikaShop 4.7.4. Attackers can inject malicious scripts by manipulating GET parameters in the product filter endpoint. This vulnerability allows unauthenticated attackers to steal session tokens or login credentials when victims visit crafted URLs. Defenders should prioritize verifying and patching vulnerable installations to preven [truncated]