joomla Modules Anywhere是joomla组织的一款模块嵌入组件。 joomla Modules Anywhere 1.0.0版本至8.4.1版本存在安全漏洞,该漏洞源于编辑器弹出窗口可能向已认证用户暴露受限模块数据,而这些用户未获得所需的模块权限或有效的请求令牌,可能导致跨站请求伪造攻击。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| regularlabs.com | Modules Anywhere extension for Joomla | 1.0.0-8.4.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| regularlabs.com | Modules Anywhere extension for Joomla | 1.0.0-8.4.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-64871 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in | |
| CVE-2026-64875 | Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension | |
| CVE-2026-64872 | Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension | |
| CVE-2026-64874 | Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension | |
| CVE-2026-64873 | Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension | |
| CVE-2026-64799 | Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere | |
| CVE-2026-64876 | Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in | |
| CVE-2026-65713 | Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension | |
| CVE-2026-65431 | Joomla Extension - regularlabs.com - Zipslip in GeoIP extension | |
| CVE-2026-65712 | Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extensio | |
| CVE-2026-65756 | Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension | |
| CVE-2026-65754 | Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension | |
| CVE-2026-65755 | Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhe | |
| CVE-2026-65430 | Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension |
No comments yet