Description
Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed. Affected versions do not distinguish trusted extension configuration from event code supplied in ordinary article content. A lower-privileged author can therefore use a documented executable feature which should be reserved for trusted authors.
Published: 2026-09-14
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: Stored Cross‑Site Scripting
Action: Apply Patch
AI Analysis

Impact

The vulnerability allows a lower‑privileged author to supply executable code through the Modals Pro extension for Joomla’s event handler options such as on-open and on-closed. The extension treats this code as trusted, storing it in the article content and rendering it in the browser without proper escaping. Consequently, any author who can publish or edit an article can embed script that will execute with the privileges of the user viewing the modal, enabling session hijacking, cookie theft, or the execution of arbitrary actions on the site. This flaw is categorised as a stored XSS attack, mapped to CWE‑79.

Affected Systems

The affected product is the Modals (Pro) extension by regularlabs.com, installed in Joomla sites that use any version older than 17.0.0. No specific build or patch numbers are mentioned beyond the version cutoff, so any deployment below 17.0.0 is potentially vulnerable.

Risk and Exploitability

The CVSS base score of 7.5 classifies the issue as high severity. The EPSS score is < 1%, and the vulnerability is not listed in the KEV catalog, implying no publicly confirmed exploits yet. Nonetheless, the nature of the flaw—a stored XSS—makes it relatively easy for an attacker with article‑author privileges to craft the malicious payload, as the code is executed in the context of any visitor to the affected page. The likely attack vector is through normal user‑generated content channels within Joomla, meaning organizations that allow article authors without stringent review controls face considerable risk.

Generated by OpenCVE AI on September 15, 2026 at 15:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Modals (Pro) extension to version 17.0.0 or later, which corrects the sanitisation of event handler options.
  • If an immediate upgrade is not feasible, remove or disable the on‑open and on‑closed event options in the extension settings to prevent user‑supplied JavaScript from being stored and rendered.
  • Restrict article‑author permissions so that only trusted users can publish content that feeds into the modal, and enforce Joomla’s built‑in output escaping or a Content Security Policy plugin to block inline scripts between user‑generated content and the modal rendering layer.

Generated by OpenCVE AI on September 15, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com modals Pro Extension For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com modals Pro Extension For Joomla

Mon, 14 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed. Affected versions do not distinguish trusted extension configuration from event code supplied in ordinary article content. A lower-privileged author can therefore use a documented executable feature which should be reserved for trusted authors.
Title Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0
Weaknesses CWE-79
References
Metrics cvssV4_0

{'score': 7.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N'}


Subscriptions

Regularlabs.com Modals Pro Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-15T04:41:10.488Z

Reserved: 2026-09-10T10:27:00.130Z

Link: CVE-2026-88853

cve-icon Vulnrichment

Updated: 2026-09-14T14:56:26.688Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T07:17:24.383

Modified: 2026-09-16T19:28:06.713

Link: CVE-2026-88853

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T15:30:16Z

Weaknesses
  • CWE-79

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')