Description
Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers.
Published: 2026-07-22
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability in several Regular Labs Joomla extensions allows a content author to inject JavaScript that executes in visitors' browsers. The flaw arises from tag‑provided custom HTML and content override fields that are not properly sanitized, enabling a Cross‑Site Scripting attack when the malicious code is rendered.

Affected Systems

The affected extensions are Articles Anywhere Pro, Modals, Modules Anywhere Pro, Tooltips, and Users Anywhere Pro from Regular Labs. Any Joomla site that has installed these extensions is potentially impacted, though the issue does not specify exact version ranges. Site administrators should verify the presence of any of these extensions in their installation.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the EPSS score of < 1% suggests a low probability of exploitation at present. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is a content author who can place malicious code in the affected fields; once stored, the script will execute in visitors’ browsers, achieving XSS. No vendor‑provided fix is documented in the current data, so administrators should consider disabling the extensions or enforcing strict HTML filtering until an update is released.

Generated by OpenCVE AI on August 2, 2026 at 17:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to the latest release of the Regular Labs extensions that address the XSS issue once it becomes available.
  • If no update is available, remove or disable the vulnerable extensions to prevent the injection vector.
  • Configure Joomla’s content filtering to sanitize custom HTML, or install a reputable XSS filtering plugin, to block unsafe markup in the affected fields.

Generated by OpenCVE AI on August 2, 2026 at 17:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://regularlabs.com/ cve-icon cve-icon
History

Mon, 27 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 5.4, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com articles Anywhere Pro Extension For Joomla
Regularlabs.com modals Extension For Joomla
Regularlabs.com modules Anywhere Pro Extension For Joomla
Regularlabs.com tooltips Extension For Joomla
Regularlabs.com users Anywhere Pro Extension For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com articles Anywhere Pro Extension For Joomla
Regularlabs.com modals Extension For Joomla
Regularlabs.com modules Anywhere Pro Extension For Joomla
Regularlabs.com tooltips Extension For Joomla
Regularlabs.com users Anywhere Pro Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers. Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers.

Wed, 22 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that ran in visitors’ browsers.
Title Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions
Weaknesses CWE-79
References

Subscriptions

Regularlabs.com Articles Anywhere Pro Extension For Joomla Modals Extension For Joomla Modules Anywhere Pro Extension For Joomla Tooltips Extension For Joomla Users Anywhere Pro Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-27T13:29:26.815Z

Reserved: 2026-07-20T18:16:31.592Z

Link: CVE-2026-64795

cve-icon Vulnrichment

Updated: 2026-07-27T13:25:13.050Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T21:18:10.660

Modified: 2026-07-27T14:16:59.660

Link: CVE-2026-64795

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T17:45:02Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')