Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intention...
regularlabs.com CVEs
19 high and critical vulnerabilities covered by CVE Brief since 2026-07-22, each with independent analyst commentary.
← All vendors RSS feed Watch this vendorProfile
Last 12 months
19 CVEs in the last 12 months
Products
- Articles Anywhere extension for Joomla3
- Sourcerer extension for Joomla2
- GeoIP extension for Joomla2
- Modals (Pro) extension for Joomla1
- Snippets (Free) extension for Joomla1
- Conditional Content Pro extension for Joomla1
- Tabs & Accordions extension for Joomla1
- Quick Index extension for Joomla1
14 products in total
Every figure counts the high and critical CVEs CVE Brief has published for this vendor, not every CVE the vendor has ever received. Exploitation means listing in the CISA Known Exploited Vulnerabilities catalog. No patch-availability figure is shown because CVE Brief does not measure it.
Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Jo...
Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere acce...
A code injection vulnerability in the Conditional Content Pro extension allows authenticated, privileged users to execute arbitrary PHP code on the se...
Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions...
Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configur...
Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destin...
The Regular Labs Sourcerer extension for Joomla is vulnerable to unauthenticated remote code execution due to improper handling of reflected user inpu...
Joomla Extension - regularlabs
A path traversal vulnerability in the Regular Labs GeoIP extension for Joomla allows for arbitrary file writes during the extraction of database updat...
Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a crede...
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.
Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.
Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce confi...
Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expo...
Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrato...
Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauth...
Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized bac...
IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.