PatchSiren

Hikashop CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Hikashop CVE published 2026-04-09

CVE-2023-54364

CVE-2023-54364 is a reflected cross-site scripting vulnerability in Joomla HikaShop 4.7.4. Attackers can inject malicious scripts by manipulating GET parameters in the product filter endpoint. This vulnerability allows unauthenticated attackers to steal session tokens or login credentials when victims visit crafted URLs. Defenders should prioritize verifying and patching vulnerable installations to preven [truncated]