Executive brief
Multiple Regular Labs extensions for the Joomla content management system are vulnerable to a security flaw where malicious code can be stored and executed. These extensions are used to manage website modules, content templates, and conditional display rules. If exploited, an attacker could execute unauthorized scripts in the web browser of a site administrator, potentially leading to account takeover or unauthorized site modifications.
Technical details
A stored cross-site scripting (XSS) vulnerability exists in several Regular Labs Joomla extensions, including Advanced Module Manager, Conditional Content, Content Templater Pro, and ReReplacer Pro. The vulnerability stems from improper neutralization of input during web page generation (CWE-79) specifically within stored condition values. An attacker with the ability to save condition configurations can inject malicious HTML or JavaScript that executes when an administrator views the summary page for these extensions. This could allow for session hijacking or unauthorized administrative actions within the Joomla backend.
Affected products
- Regular Labs Advanced Module Manager extension for Joomla 1.0.0-11.0.1
- Regular Labs Conditional Content extension for Joomla 1.0.0-6.0.0
- Regular Labs Content Templater Pro extension for Joomla 1.0.0-13.0.0
- Regular Labs ReReplacer extension Pro for Joomla 1.0.0-15.0.3
Timeline
- 2026-07-22: disclosed: CVE published by Joomla! Project and NVD