Search Results (29 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-63684 1 Regularlabs.com 3 Content Templater Extension For Joomla, Rereplacer Extension For Joomla, Snippets Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and items.
CVE-2026-64791 1 Regularlabs.com 1 Regular Labs Extension Manager Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized backend user or CSRF attack could install, update or remove extensions.
CVE-2026-63281 1 Regularlabs.com 4 Advanced Module Manager Extension For Joomla, Conditional Content Extension For Joomla, Content Templater Pro Extension For Joomla and 1 more 2026-07-23 N/A
Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values could also execute HTML/JavaScript in administrator summaries.
CVE-2026-64792 1 Regularlabs.com 7 Articles Anywhere Extension For Joomla, Conditional Content Extension For Joomla, Modules Anywhere Extension For Joomla and 4 more 2026-07-23 N/A
Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or administrator-only content could consequently be stored in the public search index and disclosed to visitors.
CVE-2026-64795 1 Regularlabs.com 5 Articles Anywhere Pro Extension For Joomla, Modals Extension For Joomla, Modules Anywhere Pro Extension For Joomla and 2 more 2026-07-23 N/A
Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers.
CVE-2026-64798 1 Regularlabs.com 1 Ip Login Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.
CVE-2026-63683 1 Regularlabs.com 4 Advanced Module Manager Extension For Joomla, Conditional Content Extension For Joomla, Content Templater Pro Extension For Joomla and 1 more 2026-07-23 N/A
Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.
CVE-2026-64796 1 Regularlabs.com 1 Sourcerer Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.
CVE-2026-63280 1 Regularlabs.com 4 Advanced Module Manager Extension For Joomla, Conditional Content Extension For Joomla, Content Templater Pro Extension For Joomla and 1 more 2026-07-23 N/A
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions.
CVE-2026-63685 1 Regularlabs.com 1 Db Replacer Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend user or CSRF attack could perform database replacements, potentially causing major data corruption or site compromise.
CVE-2026-63265 1 Regularlabs.com 23 Advanced Module Manager Extension For Joomla, Articles Anywhere Extension For Joomla, Articles Field Extension For Joomla and 20 more 2026-07-23 N/A
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke lookups or mutations outside their authorization.
CVE-2026-64797 1 Regularlabs.com 1 Ip Login Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.
CVE-2026-64794 1 Regularlabs.com 2 Articles Anywhere Extension For Joomla, Users Anywhere Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user parameters or restricted contact details.
CVE-2026-64793 1 Regularlabs.com 2 Articles Anywhere Extension For Joomla, Modules Anywhere Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished articles or modules. A content author could thereby expose content to visitors who lacked the required access.
CVE-2026-65431 1 Regularlabs.com 1 Geoip Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.
CVE-2026-65430 1 Regularlabs.com 1 Geoip Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.
CVE-2026-64799 1 Regularlabs.com 2 Articles Anywhere Pro Extension For Joomla, Users Anywhere Pro Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder.
CVE-2026-64874 1 Regularlabs.com 1 Cache Cleaner Pro Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.
CVE-2026-65756 1 Regularlabs.com 1 Keyboard Shortcuts Extension For Joomla 2026-07-23 6.1 Medium
Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.
CVE-2026-65712 1 Regularlabs.com 1 Cdn For Joomla Pro Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - Insecure path handling in CDN for Joomla Pro extension - CDN versioning could check file paths outside the site directory, exposing local file existence and modification metadata.