PatchSiren

Thethinkery CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Thethinkery CVE published 2026-04-09

CVE-2023-54361

CVE-2023-54361 is a reflected cross-site scripting vulnerability in Joomla iProperty Real Estate 4.1.1. Attackers can inject malicious scripts by manipulating the filter_keyword parameter in the all-properties-with-map endpoint. This vulnerability allows attackers to execute arbitrary code in victim browsers and steal session tokens or credentials. Defenders should prioritize verifying exposure of the fil [truncated]