Description
Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable.
Published: 2026-07-23
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw resides in Regular Labs’ Articles Anywhere and Users Anywhere extensions for Joomla where query‑cache keys fail to include a bounded time component. This weakness, catalogued as CWE‑524, permits cached results to persist beyond their intended validity, allowing unauthorized users to retrieve content that has expired or is scheduled for future publication, thus leaking sensitive time‑restricted information.

Affected Systems

Regular Labs’ Articles Anywhere and Users Anywhere extensions for Joomla. The issue affects all installations that use query caching in these extensions. No specific version information is provided, so any instance running the affected extensions remains potentially vulnerable until a patch is applied.

Risk and Exploitability

The flaw carries a CVSS score of 7.5, with an EPSS less than 1% indicating a currently low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. Based on the description, it is inferred that an attacker could exploit the lack of a bounded time component in cache keys by triggering cached queries through the Joomla web interface, thereby retrieving content that has either expired or is scheduled for future publication. The impact is limited to sensitive content exposure rather than code execution or denial of service.

Generated by OpenCVE AI on August 3, 2026 at 22:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Articles Anywhere and Users Anywhere extensions to the latest available release that addresses the cache key bug.
  • If an update is not yet available, disable query caching for these extensions or configure cache keys to enforce a bounded expiration time.
  • Review and purge cached content for any scheduled or expired articles to prevent accidental leakage.

Generated by OpenCVE AI on August 3, 2026 at 22:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://regularlabs.com/ cve-icon cve-icon
History

Wed, 29 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com articles Anywhere Extension For Joomla
Regularlabs.com users Anywhere Extension For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com articles Anywhere Extension For Joomla
Regularlabs.com users Anywhere Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable. Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable.

Thu, 23 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable.
Title Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension
Weaknesses CWE-524
References

Subscriptions

Regularlabs.com Articles Anywhere Extension For Joomla Users Anywhere Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-29T05:40:11.634Z

Reserved: 2026-07-22T20:46:13.953Z

Link: CVE-2026-65755

cve-icon Vulnrichment

Updated: 2026-07-28T14:24:10.098Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T10:16:53.143

Modified: 2026-07-28T16:20:09.810

Link: CVE-2026-65755

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:00:04Z

Weaknesses
  • CWE-524

    Use of Cache Containing Sensitive Information