Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100750— Joomla Extension - regularlabs.com - Arbitrary file read / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla

Quick assessment

Affected
regularlabs.com Modules Anywhere (Pro) extension for Joomla
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Joomla 扩展 – regularlabs.com – Joomla 模块 Modules Anywhere 1.5.0 至 9.0.5 版本中存在本地文件包含(LFI)和服务端请求伪造(SSRF)漏洞。 Modules Anywhere Pro 允许在模块标签中添加额外的属性,用以替换所选模块的任意参数。受影响版本默认启用了此功能。然而,系统在使用这些替换值时,并未验证包含该标签的内容作者身份,即未进行任何来源或权限检查。该漏洞的实际安全风险取决于所选模块如何消费被替换的参数。 以 Joomla 核心提供的

CVSS 8.5 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100750

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Joomla Extension - regularlabs.com - Arbitrary file read / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla
Source: CVE Program / CVE List V5
Vulnerability Description
Joomla Extension - regularlabs.com - LFI / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla - Modules Anywhere Pro lets additional attributes on a module tag replace arbitrary parameters of the selected module. This feature is enabled by default in affected versions. The overrides are applied without checking who authored the content containing the tag. The security effect depends on how the selected module consumes the replaced parameter. Joomla's core Feed module provides a concrete affected path: its rssurl parameter is opened by the server and accepts local file: URLs as well as network URLs.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H
Source: CVE Program / CVE List V5
Vulnerability Type
服务端请求伪造(SSRF)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
regularlabs.com Modules Anywhere (Pro) extension for Joomla 1.5.0-9.0.5 -

II. Public POCs for CVE-2026-100750

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100750

请登录查看更多情报信息。

Vendor Pages for CVE-2026-100750 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-100750

No comments yet


Leave a comment