Junglewise Threat Intelligence

CVE-2026-100750: Regular Labs Modules Anywhere arbitrary parameter injection

CVE-2026-100750 · Severity: info · Published 2026-09-28

Technologies: Regular Labs Modules Anywhere. Vendors: Regular Labs.

Executive brief

Modules Anywhere is a Joomla extension that allows modules to be placed anywhere on a website. The extension allows custom attributes on module tags to override module parameters without validating the source of the content, enabling attackers to inject malicious parameters. When combined with vulnerable modules like Joomla's core Feed module, this can lead to local file disclosure or server-side request forgery attacks.

Technical details

The vulnerability exists in Modules Anywhere versions 1.5.0 through 9.0.5, where custom attributes on module tags replace arbitrary module parameters without authorization checks on the content author. An attacker with content creation capabilities can inject malicious parameters targeting any installed module. The core Feed module is confirmed vulnerable—its rssurl parameter accepts both local file:// and network URLs, enabling local file inclusion (LFI) and server-side request forgery (SSRF) attacks when processed by the server.

Affected products

  • Regular Labs Modules Anywhere 1.5.0 to 9.0.5

Timeline

  • 2026-09-28: disclosed

References

Related threats