Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-100751— Joomla Extension - regularlabs.com - Privileged stored XSS via data-rlta-url attributes in Tabs & Accordions (Pro) 2.3.0 - 3.1.0

Quick assessment

Affected
regularlabs.com Tabs & Accordions (Free, Pro) extension for Joomla
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Joomla 扩展 - regularlabs.com - Tabs & Accordions (Pro) 2.3.0 至 3.1.0 版本中,通过 data-rlta-url 属性实现提权存储型 XSS 漏洞。Tabs & Accordions Pro 接受项目(item)的 URL 选项,并将其写入生成的 data-rlta-url 属性中。当该项目被激活时,浏览器代码会将该值传递给 window.open() 方法。受影响的版本未能拒绝可执行 JavaScript 的浏览器 URL 协议。Joomla 在过滤

CVSS 7.5 · High
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-100751

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Joomla Extension - regularlabs.com - Privileged stored XSS via data-rlta-url attributes in Tabs & Accordions (Pro) 2.3.0 - 3.1.0
Source: CVE Program / CVE List V5
Vulnerability Description
Joomla Extension - regularlabs.com - Privileged stored XSS via data-rlta-url attributes in Tabs & Accordions (Pro) 2.3.0 - 3.1.0 - Tabs & Accordions Pro accepts a url option for an item and writes it to a generated data-rlta-url attribute. The browser code passes that value to window.open() when the item is activated. Affected versions do not reject browser URL schemes which execute JavaScript. Joomla sees ordinary plugin syntax while filtering the authored article; Tabs & Accordions creates the executable browser behavior later while rendering the article.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N
Source: CVE Program / CVE List V5
Vulnerability Type
在Web页面生成时对输入的转义处理不恰当(跨站脚本)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
regularlabs.com Tabs & Accordions (Free, Pro) extension for Joomla 2.3.0-3.1.0 -

II. Public POCs for CVE-2026-100751

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-100751

请登录查看更多情报信息。

Vendor Pages for CVE-2026-100751 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-100751

No comments yet


Leave a comment