Description
Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover. In affected versions, those options become real HTML event attributes without checking the article author's trust level. The plugin syntax survives Joomla's normal Author content filter because the executable HTML is generated later.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Update Extension
AI Analysis

Impact

This vulnerability is a stored cross‑site scripting flaw in the Articles Anywhere extension for Joomla. The extension accepts link options such as onclick and onmouseover, and in versions prior to 20.0.0 those options are turned into real HTML event attributes without validating the author’s trust level. Because the plugin syntax passes Joomla’s normal author content filter, the executable HTML is generated later, allowing an attacker who can create or edit content to embed malicious JavaScript that will run in the browsers of any site visitor. The weakness maps to the common web application flaw represented by CWE‑79.

Affected Systems

The flaw affects the Free and Pro variants of the Articles Anywhere extension published by regularlabs.com, when installed on Joomla sites running any major version lower than version 20.0.0. Sites that have not upgraded to the 20.0.0 release or later, and that use.

Risk and Exploitability

The CVSS base score of 7.5 indicates moderate‑to‑high impact, primarily on confidentiality, integrity, and availability through subverted user interactions. Because the flaw is injected through site authoring, the attack requires an attacker who can add or modify content, which is a privileged action but does not require external network access. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. However, if an attacker obtains content‑author privileges, the stored XSS payload will persist and can be executed on every page that renders the affected article, potentially leading to session hijacking, defacement, or credential theft for all site visitors.

Generated by OpenCVE AI on September 15, 2026 at 15:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Articles Anywhere extension to version 20.0.0 or later, which removes the unsanitized link options.
  • If an update is not immediately possible, disable the link option feature or restrict its use to trusted administrator accounts only.
  • Apply Joomla’s content filtering or custom input validation to strip HTML event attributes from article content (for JavaScript).
  • Apply a site‑wide content sanitization plugin that blocks inline JavaScript to mitigate the risk of stored XSS until the extension is updated.

Generated by OpenCVE AI on September 15, 2026 at 15:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover. In affected versions, those options become real HTML event attributes without checking the article author's trust level. The plugin syntax survives Joomla's normal Author content filter because the executable HTML is generated later.
Title Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-14T11:24:37.565Z

Reserved: 2026-09-03T12:25:28.491Z

Link: CVE-2026-85195

cve-icon Vulnrichment

Updated: 2026-09-14T11:14:48.959Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:22.887

Modified: 2026-09-16T19:28:06.713

Link: CVE-2026-85195

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')