Description
Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values could also execute HTML/JavaScript in administrator summaries.
Published: 2026-07-22
Score: 4.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Stored condition values in the Regular Labs extension suite can contain arbitrary HTML or JavaScript that is rendered inside administrator summary pages. The vulnerability is a stored cross‑site scripting (XSS) flaw. The description does not directly state the exploitation path beyond rendering stored content, so the exact impact is limited to the execution of the injected script. Based on the nature of XSS, it is inferred that a successful exploit could run code in the context of a logged‑in administrator, which might compromise session integrity or allow the attacker to perform unauthorized actions.

Affected Systems

Joomla extensions from Regular Labs, including the Advanced Module Manager, Conditional Content, Content Templater Pro, and ReReplacer Pro. Versions affected are not specified in the current data.

Risk and Exploitability

The EPSS score is below 1 %, indicating a very low probability of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The CVSS score of 4.8 classifies it as medium severity. The likely attack vector is an authenticated administrator who can create or edit condition values, as the flaw resides in data that is displayed in administrative summaries. Successful exploitation would require an attacker to have access to the condition editing interface and to inject malicious content. The typical consequences of a stored XSS flaw, such as session hijacking or data theft, are inferred from common XSS attack patterns and are not explicitly detailed in the vendor’s description.

Generated by OpenCVE AI on August 4, 2026 at 15:39 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the Regular Labs website or update channel for a patch that removes the XSS flaw; if a patched version is released, upgrade all affected extensions (Advanced Module Manager, Conditional Content, Content Templater Pro, and ReReplacer Pro).
  • If a patch is not yet available or if an upgrade cannot be performed immediately, remove or disable the affected Regular Labs extensions to prevent the vulnerability from being exploited.
  • As a temporary measure, enable Joomla’s input filtering or install a security plugin that sanitizes or escapes data entered into the condition values, thereby reducing the likelihood that injected markup will be executed.

Generated by OpenCVE AI on August 4, 2026 at 15:39 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://regularlabs.com/ cve-icon cve-icon
History

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com advanced Module Manager Extension For Joomla
Regularlabs.com conditional Content Extension For Joomla
Regularlabs.com content Templater Pro Extension For Joomla
Regularlabs.com rereplacer Extension Pro For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com advanced Module Manager Extension For Joomla
Regularlabs.com conditional Content Extension For Joomla
Regularlabs.com content Templater Pro Extension For Joomla
Regularlabs.com rereplacer Extension Pro For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description Stored condition values could also execute HTML/JavaScript in administrator summaries. Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values could also execute HTML/JavaScript in administrator summaries.

Wed, 22 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description Stored condition values could also execute HTML/JavaScript in administrator summaries.
Title Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager
Weaknesses CWE-79
References

Subscriptions

Regularlabs.com Advanced Module Manager Extension For Joomla Conditional Content Extension For Joomla Content Templater Pro Extension For Joomla Rereplacer Extension Pro For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-27T13:28:27.279Z

Reserved: 2026-07-16T08:19:40.115Z

Link: CVE-2026-63281

cve-icon Vulnrichment

Updated: 2026-07-27T13:24:17.726Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T21:18:09.800

Modified: 2026-07-27T14:16:59.343

Link: CVE-2026-63281

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:45:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')