{"id":"CVE-2026-78077","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-78077","summary":"Joomla Extension - joomshaper.com -  Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and item configuration…","details":"Joomla Extension - joomshaper.com -  Stored Cross-Site Scripting (XSS) in MegaMenu Layout Container & Embed Inputs in Helix Ultimate < 2.2.10 - Unsanitized column and item configuration values stored within the MegaMenu layout JSON were rendered without complete contextual escaping, allowing injection of malicious HTML/JS. Stricter sanitization and tag allowlists via `InputFilter` and `htmlspecialchars` were implemented.","published":"2026-08-31T14:17:24.113","modified":"2026-08-31T19:33:11.197","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://www.joomshaper.com/joomla-templates/helixultimate"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-31T19:33:11.197"}}