Junglewise Threat Intelligence

CVE-2026-64795: Regular Labs Joomla Extensions XSS in multiple components

CVE-2026-64795 · Severity: info · CVSS 0 · Published 2026-07-22

Vendors: Regular Labs.

Executive brief

Multiple Joomla extensions from Regular Labs, used for enhancing website content with popups, tooltips, and dynamic module placement, are vulnerable to a security flaw. A person with content creation privileges could inject malicious scripts into the website. When other visitors view the affected pages, these scripts could execute in their browsers, potentially leading to unauthorized actions or data theft.

Technical details

A stored cross-site scripting (XSS) vulnerability exists in several Regular Labs extensions for Joomla, including Modals, Tooltips, and various 'Anywhere' Pro plugins. The issue stems from improper neutralization of input during web page generation (CWE-79), specifically within tag-provided custom HTML, module content/title overrides, and decoded modal or tooltip values. An attacker with content authoring permissions can bypass intended restrictions to inject unsafe markup or JavaScript. This script is then executed in the context of any user (including administrators) who views the affected content. Affected versions range across multiple products, such as Modals up to 15.0.0 and Tooltips up to 9.4.7.

Affected products

  • Regular Labs Modals extension for Joomla 1.0.0-15.0.0
  • Regular Labs Tooltips extension for Joomla 1.0.0-9.4.7
  • Regular Labs Articles Anywhere Pro extension for Joomla 1.0.0-18.0.2
  • Regular Labs Users Anywhere Pro extension for Joomla 1.0.0-1.2.7
  • Regular Labs Modules Anywhere Pro extension for Joomla 1.0.0-8.4.1

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory

References

Related threats