Description
Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions rewrites links matching an item alias into calls to its browser API. The affected renderer places the alias inside a quoted JavaScript argument in an HTML onclick attribute without securing both the JavaScript-string and HTML-attribute contexts. A crafted data-rlta-alias value can therefore change the generated handler.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Cross‑Site Scripting
Action: Patch Now
AI Analysis

Impact

The Tabs & Accordions extension for Joomla contains a privileged stored XSS flaw in its rtla‑alias option. The option value is inserted unescaped into a JavaScript string that is itself embedded in an HTML onclick attribute, allowing an attacker to craft a data‑rlta‑alias that changes the generated handler. This flaw permits the execution of arbitrary script in the browser context of any user who views the affected page, potentially enabling session hijacking, credential theft, or defacement.

Affected Systems

The vulnerability affects all installations of the regularlabs.com Tabs & Accordions extension for Joomla—both the free and the pro editions—when the extension version is less than 3.1.0. No specific Joomla version is listed, so any Joomla site using a pre‑3.1.0 Tabs & Accordions component is likely exposed.

Risk and Exploitability

The CVSS score of 7.5 indicates a high level of risk. EPSS is less than 1%, suggesting a low probability of exploitation. The vulnerability is not listed in the CISA KEV catalog, indicating no known exploits currently. The attack vector is inferred to be a privileged attacker who can supply a crafted data‑rlta‑alias value, to the affected page.

Generated by OpenCVE AI on September 15, 2026 at 15:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the Tabs & Accordions extension to version 3.1.0 or later, which removes the vulnerable rtla‑alias handling.
  • Restrict the extension’s configuration interface to trusted administrators only and review existing content for malicious data‑rlta‑alias attributes; cleanse or delete any that are present.
  • Deploy a Content Security Policy that disallows inline scripts and limits script execution to trusted domains, mitigating the impact of similar stored XSS flaws.

Generated by OpenCVE AI on September 15, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions rewrites links matching an item alias into calls to its browser API. The affected renderer places the alias inside a quoted JavaScript argument in an HTML onclick attribute without securing both the JavaScript-string and HTML-attribute contexts. A crafted data-rlta-alias value can therefore change the generated handler.
Title Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-15T04:41:01.388Z

Reserved: 2026-09-03T12:01:51.929Z

Link: CVE-2026-85191

cve-icon Vulnrichment

Updated: 2026-09-14T14:57:36.744Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:22.627

Modified: 2026-09-16T19:28:06.713

Link: CVE-2026-85191

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')