Description
Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL. The value can reach both the generated link and the iframe-loading path. Authored content can consequently become JavaScript in a visitor's browser without using Modals' separate Pro JavaScript Events feature.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

The Modals extension for Joomla incorrectly accepts URLs that use executable browser schemes such as javascript:, data:, or other non‑HTTP a URL, the code is rendered both as a link and loaded in an iframe, causing the injected JavaScript to execute in any visitor’s browser. Because the payload is stored in the modal configuration, it persists until the modal is edited or deleted, providing a persistent stored XSS vulnerability.

Affected Systems

This vulnerability affects installations of the regularlabs.com Modals extension, both Free and Pro editions, for Joomla running any version earlier than 17.0.0. Versions 17.0.0 and later are not affected.

Risk and Exploitability

The vulnerability is scored 7.5 on the CVSS v3.1 scale and has an EPSS score of <1%, indicating a low probability of exploitation yet a high severity. The vulnerability. Based on the description, it is inferred that the likely attack path involves a content editor or administrator creating or editing a modal and inserting an executable URL scheme. The stored payload causes JavaScript to execute in the browsers of any site visitor who opens the modal, which can lead to arbitrary code execution in the front‑end. In the absence of a patch, the risk to sites that rely on unpatched Modals remains significant.

Generated by OpenCVE AI on September 15, 2026 at 15:16 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Modals extension to version 17.0.0 or later, which removes support for executable URL schemes within modal destinations.
  • If an upgrade cannot be applied immediately, audit all existing modals for malicious URLs and edit or delete any that contain executable schemes until the extension is patched.
  • Configure Joomla’s security URL schemes (for example, javascript:, data:) before saving modal configurations, or restrict modal creation and editing to a trusted subset of administrators.

Generated by OpenCVE AI on September 15, 2026 at 15:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL. The value can reach both the generated link and the iframe-loading path. Authored content can consequently become JavaScript in a visitor's browser without using Modals' separate Pro JavaScript Events feature.
Title Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-15T04:45:12.525Z

Reserved: 2026-09-03T12:01:51.929Z

Link: CVE-2026-85189

cve-icon Vulnrichment

Updated: 2026-09-14T14:54:18.616Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:22.357

Modified: 2026-09-16T19:28:06.713

Link: CVE-2026-85189

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')