Executive brief
Regular Labs Cache Cleaner Pro, a tool used to manage and clear website cache in Joomla, contains a security flaw. This vulnerability allows an attacker to potentially access or manipulate files outside of the intended website directory by using specially crafted file paths for logs or cache purging. This could lead to the exposure of sensitive system files or unauthorized modification of data on the web server.
Technical details
A path traversal vulnerability (CWE-22) exists in the Regular Labs Cache Cleaner Pro extension for Joomla versions 1.0.0 through 9.7.6. The issue stems from improper validation of user-supplied input when defining custom purge and log paths, allowing these paths to resolve to locations outside of the intended webroot directory. An attacker with sufficient privileges to modify extension settings could exploit this to read or potentially delete files elsewhere on the server filesystem. The vulnerability was reported by the Joomla! Project and affects the Pro version of the extension.
Affected products
- Regular Labs Cache Cleaner Pro extension for Joomla 1.0.0 through 9.7.6
Timeline
- 2026-07-23: disclosed
- 2026-07-23: advisory