Joomla 扩展 – regularlabs.com – Modals Pro 扩展(Joomla < 17.0.0)通过“事件处理程序选项”导致的高权限存储型跨站脚本(XSS)漏洞 Modals Pro 扩展有意支持 JavaScript 事件(例如 on-open 和 on-closed)。受影响的版本未能区分受信任的扩展配置与在普通文章内容中提供的事件代码。因此,权限较低的作者可以利用该文档中记录的、本应仅保留给受信任作者使用的可执行功能,从而触发漏洞。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| regularlabs.com | Modals (Pro) extension for Joomla | 4.7.0-16.2.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-85192 | 9.4 CRITICAL | Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Co |
| CVE-2026-85195 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Any |
| CVE-2026-85191 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & |
| CVE-2026-85190 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index |
| CVE-2026-85189 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in M |
| CVE-2026-88852 | 7.5 HIGH | Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free |
| CVE-2026-85188 | 6.9 MEDIUM | Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager ( |
| CVE-2026-85196 | 5.3 MEDIUM | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joom |
No comments yet