EIP-2026-108261

PRE-CVE

Joomla! Component com_alfcontact 1.9.3 - Multiple Cross-Site Scripting Vulnerabilities

Title source: legacy
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for EIP-2026-108261. PoCs published by Jose Carlos de Arriba.

AI-analyzed exploit summary The provided code demonstrates a cross-site scripting (XSS) vulnerability in the Joomla! 'com_alfcontact' extension by injecting malicious JavaScript into multiple input parameters. The payload triggers a prompt displaying the user's cookies when the mouse hovers over the affected fields.

Description

Joomla! Component com_alfcontact 1.9.3 - Multiple Cross-Site Scripting Vulnerabilities

Exploits (1)

exploitdb WORKING POC VERIFIED
by Jose Carlos de Arriba · textwebappsphp
https://www.exploit-db.com/exploits/36298

The provided code demonstrates a cross-site scripting (XSS) vulnerability in the Joomla! 'com_alfcontact' extension by injecting malicious JavaScript into multiple input parameters. The payload triggers a prompt displaying the user's cookies when the mouse hovers over the affected fields.

Classification
Working Poc 90%
Attack Type
Xss
Complexity
Trivial
Reliability
Reliable
Target: Joomla! 'com_alfcontact' extension 1.9.3 (and prior versions)
No auth needed
Prerequisites: Access to a vulnerable Joomla! instance with the 'com_alfcontact' extension installed
MITRE ATT&CK
devstral-2 · analyzed Feb 18, 2026 Full analysis →

Details

Status pre_cve
Tracked Since Feb 18, 2026