Junglewise Threat Intelligence

CVE-2026-63281: Regular Labs Joomla Extensions stored XSS in administrator summaries

CVE-2026-63281 · Severity: info · Published 2026-07-22

Technologies: Regular Labs Content Templater Pro, Regular Labs Advanced Module Manager, Regular Labs Conditional Content, Regular Labs ReReplacer Pro. Vendors: Regular Labs.

Executive brief

Multiple Regular Labs extensions for the Joomla content management system are vulnerable to a security flaw where malicious code can be stored and executed. These extensions are used to manage website modules, content templates, and conditional display rules. If exploited, an attacker could execute unauthorized scripts in the web browser of a site administrator, potentially leading to account takeover or unauthorized site modifications.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in several Regular Labs Joomla extensions, including Advanced Module Manager, Conditional Content, Content Templater Pro, and ReReplacer Pro. The vulnerability stems from improper neutralization of input during web page generation (CWE-79) specifically within stored condition values. An attacker with the ability to save condition configurations can inject malicious HTML or JavaScript that executes when an administrator views the summary page for these extensions. This could allow for session hijacking or unauthorized administrative actions within the Joomla backend.

Affected products

  • Regular Labs Advanced Module Manager extension for Joomla 1.0.0-11.0.1
  • Regular Labs Conditional Content extension for Joomla 1.0.0-6.0.0
  • Regular Labs Content Templater Pro extension for Joomla 1.0.0-13.0.0
  • Regular Labs ReReplacer extension Pro for Joomla 1.0.0-15.0.3

Timeline

  • 2026-07-22: disclosed: CVE published by Joomla! Project and NVD

References

Related threats