Joomla 扩展 – regularlabs.com – Joomla 17.0.0 之前的 Modals 扩展中的特权存储型跨站脚本攻击(XSS) Modals 扩展将使用可执行浏览器 URL 协议(如 、 等)的目标地址当作普通的模态框 URL 处理。该值既能进入生成的链接,也能进入 iframe 加载路径。因此,由内容作者创建的内容可以直接在访问者的浏览器中执行 JavaScript,无需使用 Modals 单独的 Pro JavaScript Events 功能。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| regularlabs.com | Modals (Free, Pro) extension for Joomla | 4.0.0-16.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85192 | 9.4 CRITICAL | Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Co |
| CVE-2026-85195 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Any |
| CVE-2026-85191 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & |
| CVE-2026-88853 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Mod |
| CVE-2026-85190 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index |
| CVE-2026-88852 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free |
| CVE-2026-85188 | 6.9 MEDIUM | Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager ( |
| CVE-2026-85196 | 5.3 MEDIUM | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joom |
No comments yet