Executive brief
A vulnerability in the Regular Labs Articles Anywhere and Users Anywhere extensions for Joomla could allow sensitive or expired content to remain visible to users. These extensions are used to display article and user information across a website; due to a caching error, content that should have been hidden or expired may still be served from the cache. This could lead to the unintended exposure of private information or outdated content that was supposed to be restricted.
Technical details
The vulnerability is classified as CWE-524 (Use of Cache Containing Sensitive Information). In affected versions of the Articles Anywhere and Users Anywhere extensions for Joomla, date-sensitive query cache keys do not include a bounded time component. This flaw causes cached results to remain valid even after a publication or expiry boundary has passed. Consequently, an attacker or general user could access content via the cache that should have been rendered unavailable by the system's time-based access controls. The issue affects Articles Anywhere versions 1.0.0 through 18.0.2 and Users Anywhere versions 1.0.0 through 1.2.7.
Affected products
- Regular Labs Articles Anywhere extension for Joomla 1.0.0-18.0.2
- Regular Labs Users Anywhere extension for Joomla 1.0.0-1.2.7
Timeline
- 2026-07-23: disclosed: CVE published by Joomla! Project