Joomla 扩展 - regularlabs.com - Articles Anywhere 扩展(Joomla < 20.0.0)和 Users Anywhere 扩展(Joomla < 2.1.0)存在反射型跨站脚本攻击(XSS)漏洞。 在 Articles Anywhere Pro 和 Users Anywhere Pro 中,该扩展直接返回来自请求输入数据标签的值,但未根据标签实际使用的上下文对这些值进行安全处理。Joomla 默认的字符串输入过滤器无法确保同一值在 HTML 文本、HTML 属性或 UR
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| regularlabs.com | Articles Anywhere (Pro) extension for Joomla | 8.4.0-19.0.6 | - |
|
| regularlabs.com | Users Anywhere (Pro) extension for Joomla | 1.0.0-2.0.6 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85192 | 9.4 CRITICAL | Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Co |
| CVE-2026-85195 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Any |
| CVE-2026-85191 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & |
| CVE-2026-88853 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Mod |
| CVE-2026-85190 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index |
| CVE-2026-85189 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in M |
| CVE-2026-88852 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free |
| CVE-2026-85188 | 6.9 MEDIUM | Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager ( |
No comments yet