Junglewise Threat Intelligence

CVE-2026-65754: Regular Labs ReReplacer Pro path traversal in XML include paths

CVE-2026-65754 · Severity: info · Published 2026-07-23

Technologies: Regular Labs ReReplacer Pro. Vendors: Regular Labs.

Executive brief

ReReplacer is a popular Joomla extension used to automate search-and-replace tasks across website content. A security flaw in how the extension handles XML include paths allows an attacker to potentially access sensitive files stored on the server outside of the intended website directory. This could lead to the exposure of configuration files, credentials, or other private data, compromising the security of the entire web server.

Technical details

A path traversal vulnerability (CWE-22) exists in the Regular Labs ReReplacer Pro extension for Joomla, specifically within the handling of XML include paths. The application fails to properly sanitize or restrict file paths provided in XML configurations, allowing an attacker to reference files outside the intended site directory. This vulnerability affects versions 1.0.0 through 15.0.3. By exploiting this flaw, a remote attacker could potentially read sensitive system files or application source code, depending on the permissions of the web server process.

Affected products

  • Regular Labs ReReplacer Pro extension for Joomla 1.0.0 through 15.0.3

Timeline

  • 2026-07-23: disclosed: CVE published by Joomla! Project
  • 2026-07-23: advisory

References

Related threats