CVE-2014-1837

Joomla! com_komento <1.7.4 - XSS

Title source: llm

Description

Cross-site scripting (XSS) vulnerability in the StackIdeas Komento (com_komento) component before 1.7.4 for Joomla! allows remote attackers to inject arbitrary web script or HTML via vectors related to "checking new comments."

Scores

EPSS 0.0036
EPSS Percentile 57.7%

Details

CWE
CWE-79
Status published
Products (5)
stackideas/komento < 1.7.3
stackideas/komento
stackideas/komento
stackideas/komento
n/a/n/a
Published Jan 30, 2014
Tracked Since Feb 18, 2026