Description
Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. A crafted value can close the intended class attribute and introduce a new attribute. Joomla's content filter cannot reliably prevent this because Quick Index creates the executable HTML after the authored plugin syntax was filtered.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored XSS
Action: Apply Patch
AI Analysis

Impact

The Quick Index extension for Joomla allows configuration of a CSS class that is inserted directly into generated HTML. The option value is not escaped, so a crafted input can close the class attribute and inject a new attribute, permitting arbitrary script to be stored and executed whenever the page is viewed. This stored cross‑site scripting vulnerability (CWE‑79) provides attackers with the ability to steal session cookies, hijack user sessions, a privileged user (e.g., an administrator or content author) injects the payload.

Affected Systems

The vulnerability affects both the Free and Pro versions of the Quick Index extension sold by regularlabs.com for Joomla platforms running any version All sites that have installed Quick Index before the 5.0.5 release are potentially impacted.

Risk and Exploitability

Because the flaw is stored, an attacker must first be able to insert the malicious value via the extension’s administrative interface, which typically requires at least content‑author privileges. Once the payload is stored, it is rendered in the browser of any user who views the affected page, enabling cross‑site scripting without additional user interaction. The CVSS score of 7.5, EPSS score of 0.00247 (<1%) indicates a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet but a still significant risk based on the potential impact and required privileges.

Generated by OpenCVE AI on September 15, 2026 at 15:15 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Quick Index extension to version 5.0.5 or newer, which patches the unescaped class handling.
  • If an upgrade is not possible, restrict the class option setting to administrator users only and audit existing values for malicious content.
  • Implement a custom filter or manually patch the the page.

Generated by OpenCVE AI on September 15, 2026 at 15:15 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 07:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. A crafted value can close the intended class attribute and introduce a new attribute. Joomla's content filter cannot reliably prevent this because Quick Index creates the executable HTML after the authored plugin syntax was filtered.
Title Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-15T04:46:08.478Z

Reserved: 2026-09-03T12:01:51.929Z

Link: CVE-2026-85190

cve-icon Vulnrichment

Updated: 2026-09-14T11:32:19.696Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:22.490

Modified: 2026-09-16T19:28:06.713

Link: CVE-2026-85190

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')