PatchSiren

Virtuemart CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM Virtuemart CVE published 2026-04-09

CVE-2023-54362

CVE-2023-54362 is a reflected cross-site scripting vulnerability in Joomla VirtueMart Shopping-Cart 4.0.12. Attackers can inject malicious scripts by manipulating the keyword parameter in the product-variants endpoint, allowing for arbitrary JavaScript execution in victim browsers. This vulnerability has a CVSS score of 5.1 and a severity of MEDIUM. Defenders should prioritize verifying and patching vulne [truncated]