19 Total CVEs
19 AI Analyzed
0 CISA KEV
7 Critical

Profile

0% ended up actively exploited 0 of 19 added to CISA KEV
37% rated critical (CVSS 9.0+) 7 critical, 12 high
0 with a public exploit on record positive-only index; absence is not proof

Last 12 months

19 CVEs in the last 12 months

Products

  • Articles Anywhere extension for Joomla3
  • Sourcerer extension for Joomla2
  • GeoIP extension for Joomla2
  • Modals (Pro) extension for Joomla1
  • Snippets (Free) extension for Joomla1
  • Conditional Content Pro extension for Joomla1
  • Tabs & Accordions extension for Joomla1
  • Quick Index extension for Joomla1

14 products in total

Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.

All Vendors
Showing 1-19 of 19 CVEs
CVE-2026-88853
Analyzed
7.5
regularlabs.com Modals (Pro) extension for Joomla

Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intention...

2026-09-14
Full analysis →
CVE-2026-88852
Analyzed
7.5
regularlabs.com Snippets (Free) extension for Joomla

Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Jo...

2026-09-14
Full analysis →
CVE-2026-85195
Analyzed
7.5
regularlabs.com Articles Anywhere extension for Joomla

Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere acce...

2026-09-14
Full analysis →
CVE-2026-85192
Analyzed
9.4
regularlabs.com Conditional Content Pro extension for Joomla

A code injection vulnerability in the Conditional Content Pro extension allows authenticated, privileged users to execute arbitrary PHP code on the se...

2026-09-14
Full analysis →
CVE-2026-85191
Analyzed
7.5
regularlabs.com Tabs & Accordions extension for Joomla

Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions...

2026-09-14
Full analysis →
CVE-2026-85190
Analyzed
7.5
regularlabs.com Quick Index extension for Joomla

Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configur...

2026-09-14
Full analysis →
CVE-2026-85189
Analyzed
7.5
regularlabs.com Modals (Free, Pro) extension for Joomla

Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destin...

2026-09-14
Full analysis →
CVE-2026-74253
Analyzed
10
regularlabs.com Sourcerer extension for Joomla

The Regular Labs Sourcerer extension for Joomla is vulnerable to unauthenticated remote code execution due to improper handling of reflected user inpu...

2026-08-18
Full analysis →
CVE-2026-65431
Analyzed
9.8
regularlabs.com GeoIP extension for Joomla

A path traversal vulnerability in the Regular Labs GeoIP extension for Joomla allows for arbitrary file writes during the extraction of database updat...

2026-08-02
Full analysis →
CVE-2026-65430
Analyzed
7.5
regularlabs.com GeoIP extension for Joomla

Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a crede...

2026-08-02
Full analysis →
CVE-2026-64873
Analyzed
9.8
regularlabs.com Cache Cleaner Pro extension for Joomla

Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.

2026-08-03
Full analysis →
CVE-2026-64798
Analyzed
9.1
regularlabs.com IP Login extension for Joomla

Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.

2026-08-14
Full analysis →
CVE-2026-64796
Analyzed
9.8
regularlabs.com Sourcerer extension for Joomla

Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce confi...

2026-08-13
Full analysis →
CVE-2026-64793
Analyzed
9.1
regularlabs.com Articles Anywhere extension for Joomla

Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expo...

2026-08-13
Full analysis →
CVE-2026-64792
Analyzed
7.5
regularlabs.com Articles Anywhere extension for Joomla

Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrato...

2026-08-15
Full analysis →
CVE-2026-64791
Analyzed
8.8
regularlabs.com

Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauth...

2026-08-14
Full analysis →
CVE-2026-63684
Analyzed
8.8
regularlabs.com Content Templater extension for Joomla

Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized bac...

2026-08-14
Full analysis →
CVE-2026-63683
Analyzed
7.5
regularlabs.com Advanced Module Manager extension for Joomla

IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.

2026-08-01
Full analysis →