Description
Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.
Published: 2026-07-23
Score: 6.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Joomla Extension 'Keyboard Shortcuts' by regularlabs.com allows configuration of shortcuts via administrative interface that accepts arbitrary inline JavaScript. An attacker who can edit shortcut entries can inject malicious script that will run in the browsers of users who view content protected by the extension. This leads to cross‑site scripting, enabling theft of session cookies, defacement, or other malicious client‑side actions.

Affected Systems

This vulnerability impacts the Keyboard Shortcuts extension for Joomla supplied by regularlabs.com; any installation of the extension that has not applied the latest patch removes the inline JavaScript storage vulnerability. No specific version numbers were listed, so all unpatched installations of the extension are potentially affected.

Risk and Exploitability

The CVSS score of 6.1 classifies the flaw as medium severity, and the EPSS score of less than 1 percent indicates a low likelihood of exploitation at the time of analysis. The vulnerability is not yet catalogued in CISA KEV, suggesting no current known public exploits. Exploitation requires access to the Joomla administrative backend or a content editor with shortcut editing rights; the extent of damage depends on the privileges of the attacker’s account and the breadth of user exposure to the injected script.

Generated by OpenCVE AI on August 5, 2026 at 01:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade the Keyboard Shortcuts extension to a version that removes the inline JavaScript injection flaw
  • If a patch is not yet available, remove or sanitize any shortcut entries that contain JavaScript or replace them with safe text
  • Restrict access to the Joomla administrative backend so that only trusted users can modify the Keyboard Shortcuts extension settings

Generated by OpenCVE AI on August 5, 2026 at 01:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
Link Providers
https://regularlabs.com/ cve-icon cve-icon
History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com keyboard Shortcuts Extension For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com keyboard Shortcuts Extension For Joomla
Metrics cvssV3_1

{'score': 6.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description Shortcut configuration accepted arbitrary inline JavaScript. Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.

Thu, 23 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description Shortcut configuration accepted arbitrary inline JavaScript.
Title Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension
Weaknesses CWE-79
References

Subscriptions

Regularlabs.com Keyboard Shortcuts Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-24T07:17:56.388Z

Reserved: 2026-07-22T20:46:13.953Z

Link: CVE-2026-65756

cve-icon Vulnrichment

Updated: 2026-07-23T19:08:41.503Z

cve-icon NVD

Status : Deferred

Published: 2026-07-23T10:16:53.253

Modified: 2026-07-23T20:17:22.407

Link: CVE-2026-65756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T01:15:03Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')