Joomla 扩展 — regularlabs.com — Tabs & Accordions 扩展(Joomla < 3.1.0 版本)中的“rtla-alias”选项存在特权型存储型跨站脚本(Stored XSS)漏洞。Tabs & Accordions 扩展会将与项目别名(item alias)匹配的链接重写为其浏览器 API 调用。受影响的渲染器将别名放在 HTML 的 onclick 属性中一个带引号的 JavaScript 参数内部,却未同时保护 JavaScript 字符串上下文和 HTML 属性上下
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| regularlabs.com | Tabs & Accordions (Free, Pro) extension for Joomla | 1.0.0-3.0.5 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85192 | 9.4 CRITICAL | Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Co |
| CVE-2026-85195 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Any |
| CVE-2026-88853 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Mod |
| CVE-2026-85190 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index |
| CVE-2026-85189 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in M |
| CVE-2026-88852 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free |
| CVE-2026-85188 | 6.9 MEDIUM | Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager ( |
| CVE-2026-85196 | 5.3 MEDIUM | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joom |
No comments yet