Joomla 扩展 - regularlabs.com - 认证的高权限远程代码执行漏洞,影响版本:Joomla 8.0.0 之前的“Conditional Content”扩展。 “Conditional Content Pro”扩展支持在文章语法中使用内联 PHP 条件规则。在受影响版本中,这些 PHP 代码会被直接传递给条件评估器执行,而未验证文章的作者身份。由于 Joomla 默认的“Author”文本过滤器会保留该语法,因此当文章被发布时,所嵌代码将以 Web 服务器进程的身份执行,从而导致已认证且具有特
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| regularlabs.com | Conditional Content Pro extension for Joomla | 1.0.0-7.1.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85195 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Any |
| CVE-2026-85191 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & |
| CVE-2026-88853 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Mod |
| CVE-2026-85190 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index |
| CVE-2026-85189 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in M |
| CVE-2026-88852 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free |
| CVE-2026-85188 | 6.9 MEDIUM | Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager ( |
| CVE-2026-85196 | 5.3 MEDIUM | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joom |
No comments yet