<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:media="http://search.yahoo.com/mrss/">
  <channel>
    <title>regularlabs.com CVEs · CVE Brief</title>
    <link>https://cvebrief.com/archive/cves/vendor/regularlabs-com/</link>
    <atom:link href="https://cvebrief.com/feeds/vendor/regularlabs-com.xml" rel="self" type="application/rss+xml"/>
    <description>High and critical regularlabs.com vulnerabilities covered by CVE Brief, with independent analyst commentary.</description>
    <language>en-us</language>
    <lastBuildDate>Mon, 14 Sep 2026 12:00:00 GMT</lastBuildDate>
    <item>
      <title>CVE-2026-85189 · CVSS 7.5 · Modals (Free, Pro) extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-85189/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-85189</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla &lt; 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-85190 · CVSS 7.5 · Quick Index extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-85190/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-85190</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla &lt; 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-85191 · CVSS 7.5 · Tabs &amp; Accordions extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-85191/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-85191</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs &amp; Accordions extension for Joomla &lt; 3.1.0 - Tabs &amp; Accordions rewrites links matching an item alias into calls to its browser API. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-85192 · CVSS 9.4 · Conditional Content Pro extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-85192/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-85192</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
      <description>A code injection vulnerability in the Conditional Content Pro extension allows authenticated, privileged users to execute arbitrary PHP code on the server via malicious article syntax. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-85195 · CVSS 7.5 · Articles Anywhere extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-85195/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-85195</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla &lt; 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-88852 · CVSS 7.5 · Snippets (Free) extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-88852/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-88852</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla &lt; 7.0.0, Snippets Pro extension for Joomla &lt; 11.0.0 - Snippets substitutes variable values supplied by an article tag into saved Snippet content. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-88853 · CVSS 7.5 · Modals (Pro) extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-88853/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-88853</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Mon, 14 Sep 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla &lt; 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-74253 · CVSS 10.0 · Sourcerer extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-74253/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-74253</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Tue, 18 Aug 2026 12:00:00 GMT</pubDate>
      <description>The Regular Labs Sourcerer extension for Joomla is vulnerable to unauthenticated remote code execution due to improper handling of reflected user input within rendered HTML blocks. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-64792 · CVSS 7.5 · Articles Anywhere extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-64792/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-64792</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Sat, 15 Aug 2026 12:00:00 GMT</pubDate>
      <description>Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-63684 · CVSS 8.8 · Content Templater extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-63684/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-63684</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Fri, 14 Aug 2026 12:00:00 GMT</pubDate>
      <description>Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-64791 · CVSS 8.8</title>
      <link>https://cvebrief.com/cve/cve-2026-64791/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-64791</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Fri, 14 Aug 2026 12:00:00 GMT</pubDate>
      <description>Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-64798 · CVSS 9.1 · IP Login extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-64798/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-64798</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Fri, 14 Aug 2026 12:00:00 GMT</pubDate>
      <description>Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-64793 · CVSS 9.1 · Articles Anywhere extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-64793/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-64793</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Thu, 13 Aug 2026 12:00:00 GMT</pubDate>
      <description>Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-64796 · CVSS 9.8 · Sourcerer extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-64796/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-64796</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Thu, 13 Aug 2026 12:00:00 GMT</pubDate>
      <description>Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-64873 · CVSS 9.8 · Cache Cleaner Pro extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-64873/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-64873</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Mon, 03 Aug 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-65430 · CVSS 7.5 · GeoIP extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-65430/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-65430</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-65431 · CVSS 9.8 · GeoIP extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-65431/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-65431</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Sun, 02 Aug 2026 12:00:00 GMT</pubDate>
      <description>A path traversal vulnerability in the Regular Labs GeoIP extension for Joomla allows for arbitrary file writes during the extraction of database update archives. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-63683 · CVSS 7.5 · Advanced Module Manager extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-63683/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-63683</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Sat, 01 Aug 2026 12:00:00 GMT</pubDate>
      <description>IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules. Independent analyst report on CVE Brief.</description>
    </item>
    <item>
      <title>CVE-2026-65757 · CVSS 8.1 · Modules Anywhere extension for Joomla</title>
      <link>https://cvebrief.com/cve/cve-2026-65757/?utm_source=cvebrief&amp;utm_medium=rss&amp;utm_campaign=vendor-feed</link>
      <guid isPermaLink="false">cvebrief-regularlabs-com-CVE-2026-65757</guid>
      <media:content url="https://cvebrief.com/feeds/vendor/regularlabs-com.png" medium="image" type="image/png"/>
      <pubDate>Sat, 25 Jul 2026 12:00:00 GMT</pubDate>
      <description>Joomla Extension - regularlabs Independent analyst report on CVE Brief.</description>
    </item>
  </channel>
</rss>
