Joomla 插件 — regularlabs.com — Quick Index 插件(适用于 Joomla < 5.0.5)通过“class”选项实现的特权型存储型 XSS 漏洞 Quick Index 插件将可配置的 值直接插入到生成的 HTML 中,且未对 HTML 属性进行转义。攻击者可以构造一个特殊的值,从而结束预设的 属性并引入新的属性。由于 Quick Index 在作者插件语法经过内容过滤器处理之后才生成可执行的 HTML,因此 Joomla 的内容过滤器无法可靠地阻止此漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| regularlabs.com | Quick Index (Free, Pro) extension for Joomla | 1.0.0-5.0.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85192 | 9.4 CRITICAL | Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Co |
| CVE-2026-85195 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Any |
| CVE-2026-85191 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & |
| CVE-2026-88853 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Mod |
| CVE-2026-85189 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in M |
| CVE-2026-88852 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free |
| CVE-2026-85188 | 6.9 MEDIUM | Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager ( |
| CVE-2026-85196 | 5.3 MEDIUM | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joom |
No comments yet