CVE-2009-4651 EXPLOIT
4.3
MEDIUM · CVSS 2.0 · EPSS 1.2% (pctl 67)
Patch early
A public exploit exists.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the Webee Comments (com_webeecomment) component 1.1.1, 1.2, and 2.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) color, (2) img, or (3) url BBCode tags in unspecified vectors.
Scoring
| CVSS | 4.3 (MEDIUM, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:N/I:P/A:N |
| EPSS | 1.18% — more likely to be exploited than 67% of all CVEs |
| Weakness | CWE-79 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2010-02-22 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| joomla | joomla\! |
| onnogroen | com webeecomment |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Joomla! Component Webee Comments 1.1/1.2 - Multiple BBCode Tags Cross-Site Scripting Vulnerabilities | 2009-11-15 |
References
→ the Explorer · watch your stack · NVD