Impact
The vulnerability originates from the Regular Labs Snippets extension’s handling of article‑supplied variables. When an article tag supplies a value for the URL option, the Snippets module stores that value directly into snippet content without validating the author’s trust level. A lower‑privileged which a higher‑privileged snippet author then renders as part of a snippet. When the snippet is displayed on a page, the injected code executes in the viewer’s browser, giving the attacker client‑side code execution in the context of the site.
Affected Systems
Regular Labs Snippets Free extension for Joomla versions earlier than 7.0.0, and Regular Labs Snippets Pro extension for Joomla versions earlier than 11.0.0. Both variants embed unsanitized article‑supplied values into snippet content and ignore the author’s privilege level.
Risk and Exploitability
The CVSS base score of 7.5 places this issue in the medium‑high severity range, while the EPSS score of <1% indicates a very low but nonzero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. Attackers who can create or edit Joomla articles containing the snippet tag can inject malicious input, and once the snippet is rendered it will execute in the browser of any visitor, exposing the site to stored cross‑site scripting.
OpenCVE Enrichment