Description
Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.
Published: 2026-07-22
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Sourcerer extension for Joomla allows administrators to embed arbitrary PHP, JavaScript, or CSS directly within article content. In the Free edition, the code handling article PHP execution does not require the article creator and last modifier to be Super Users, enabling non‑privileged editors to run PHP. In the Pro edition, the extension does not consistently enforce CSS, JavaScript, or PHP permission settings across tags, attributes, files and article owners, and PHP include attributes can escape the configured include folder. These weaknesses, represented by CWE‑284, can allow an attacker to inject executable code and upload files that bypass detection, leading to code execution or privileged actions.

Affected Systems

Joomla sites that have installed the Sourcerer extension from regularlabs.com. Both the Free and Pro editions are affected; version information is not specified in the advisory.

Risk and Exploitability

The CVSS score of 9.8 categorises this vulnerability as critical. The EPSS score of less than 1 % indicates a very low likelihood of exploitation in the wild, and the absence from the CISA KEV catalog suggests no publicly known exploits yet. An attacker can exploit the flaw by injecting malicious PHP, JavaScript or CSS through the Joomla administrative interface, because the extension bypasses the configured permission checks. If successful, the attacker could execute code in the context of the site, potentially gaining full control.

Generated by OpenCVE AI on August 2, 2026 at 17:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install the vendor‑issued patch or upgrade the Sourcerer extension to the latest available version.
  • Ensure that only Super Users can create or edit content containing PHP, JavaScript or CSS in the extension settings.
  • Disable or tightly restrict the PHP inclusion feature and limit the include directory to a safe path.
  • Review and tighten CSS, JavaScript and PHP permission settings to match the intended access level.
  • Monitor the site for unexpected script execution or file modifications, reviewing Joomla logs for suspicious activity.

Generated by OpenCVE AI on August 2, 2026 at 17:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://regularlabs.com/ cve-icon cve-icon
History

Tue, 28 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com sourcerer Extension For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com sourcerer Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection. Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.

Wed, 22 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Description Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.
Title Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension
Weaknesses CWE-284
References

Subscriptions

Regularlabs.com Sourcerer Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-28T05:34:08.793Z

Reserved: 2026-07-20T18:16:31.593Z

Link: CVE-2026-64796

cve-icon Vulnrichment

Updated: 2026-07-27T18:43:46.172Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T21:18:10.763

Modified: 2026-07-27T19:17:21.777

Link: CVE-2026-64796

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T17:30:17Z

Weaknesses