Executive brief
Multiple Regular Labs extensions for the Joomla content management system contain security flaws that could allow unauthorized users to modify website content or settings. These extensions are used to manage templates, search-and-replace functions, and content snippets. An attacker could potentially exploit these weaknesses to change site configurations or gain access to sensitive administrative data.
Technical details
The Content Templater, ReReplacer, and Snippets extensions for Joomla fail to consistently implement CSRF tokens, item-level permission checks, and input validation across administrator actions, editor popups, and import/export requests. This vulnerability (CWE-284 and CWE-352) allows unauthorized backend users or remote attackers (via Cross-Site Request Forgery) to expose, create, or modify extension configurations and items. The issue stems from inconsistent enforcement of security controls in the backend components of these extensions. Users should update to versions beyond the affected ranges specified by the vendor.
Affected products
- Regular Labs Content Templater extension for Joomla 1.0.0-13.0.0
- Regular Labs ReReplacer extension for Joomla 1.0.0-15.0.3
- Regular Labs Snippets extension for Joomla 1.0.0-9.3.10
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory