Impact
This vulnerability in several Regular Labs Joomla extensions allows a content author to inject JavaScript that executes in visitors' browsers. The flaw arises from tag‑provided custom HTML and content override fields that are not properly sanitized, enabling a Cross‑Site Scripting attack when the malicious code is rendered.
Affected Systems
The affected extensions are Articles Anywhere Pro, Modals, Modules Anywhere Pro, Tooltips, and Users Anywhere Pro from Regular Labs. Any Joomla site that has installed these extensions is potentially impacted, though the issue does not specify exact version ranges. Site administrators should verify the presence of any of these extensions in their installation.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity, and the EPSS score of < 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a content author who can place malicious code in the affected fields; once stored, the script will execute in visitors’ browsers, achieving XSS. No vendor‑provided fix is documented in the current data, so administrators should consider disabling the extensions or enforcing strict HTML filtering until an update is released.
OpenCVE Enrichment