Description
Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.
Published: 2026-07-23
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability is a server-side request forgery that allows an attacker to craft custom query URLs in the Cache Cleaner Pro extension for Joomla. By causing the extension to send HTTP requests to arbitrary internal or reserved network services, the flaw could expose sensitive information or allow the attacker to perform operations against internal services. The weakness is identified as CWE-918, indicating an ability to force the application to access internal resources that should be hidden from the attacker.

Affected Systems

The affected product is the Cache Cleaner Pro extension for Joomla, distributed by regularlabs.com. No specific version information is supplied in the data; users should verify the installed extension version against the vendor’s release notes.

Risk and Exploitability

The CVSS score of 9.8 marks this flaw as critical, with high potential impact on confidentiality and integrity. The EPSS score of < 1 % suggests a low current probability of exploitation, but the vulnerability remains dangerous once discovered. It is not listed in the CISA KEV catalog. The likely attack vector is through the extension’s query URL functionality, which can be invoked by any user who can interact with the extension’s interface. Although exploitation prerequisites are not detailed, the flaw can be triggered without authentication in many typical Joomla deployments, making the risk significant.

Generated by OpenCVE AI on August 4, 2026 at 15:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact the vendor to obtain a patched version of the Cache Cleaner Pro extension or subscribe to the vendor’s update service.
  • If a patch is unavailable, disable or uninstall the Cache Cleaner Pro extension until a fix is released.
  • Configure web application firewall rules to block outbound requests from the Joomla application to internal or reserved IP ranges.

Generated by OpenCVE AI on August 4, 2026 at 15:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://regularlabs.com/ cve-icon cve-icon
History

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com cache Cleaner Pro Extension For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com cache Cleaner Pro Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description Custom query URLs could access internal or reserved network services. Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.

Thu, 23 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description Custom query URLs could access internal or reserved network services.
Title Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension
Weaknesses CWE-918
References

Subscriptions

Regularlabs.com Cache Cleaner Pro Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-25T05:34:58.799Z

Reserved: 2026-07-20T18:35:16.486Z

Link: CVE-2026-64873

cve-icon Vulnrichment

Updated: 2026-07-24T19:37:38.556Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T10:16:52.193

Modified: 2026-07-24T20:18:19.837

Link: CVE-2026-64873

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:45:03Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)