Junglewise Threat Intelligence

CVE-2026-74253: Regular Labs Sourcerer RCE in unverified reflected input

CVE-2026-74253 · Severity: info · Published 2026-08-17

Technologies: Regular Labs Sourcerer. Vendors: Regular Labs.

Executive brief

Regular Labs Sourcerer is a popular Joomla extension that allows administrators to embed custom code into Joomla pages. A vulnerability in versions before 16.0.0 allows unauthenticated attackers to execute arbitrary code by injecting malicious input that is reflected in the final HTML without proper validation. An attacker could gain complete control over the affected Joomla website and access sensitive data or deface content.

Technical details

The vulnerability is a reflected code injection issue in Sourcerer's handling of {source} blocks. The extension processes these blocks in Joomla's final rendered HTML without reliably verifying the source or origin of the injected code, allowing an unauthenticated attacker to craft and reflect malicious input through the application. The attack requires no authentication and is reachable via the network. A successful exploit allows remote code execution (RCE) with the privileges of the Joomla application. The vulnerability is fixed in version 16.0.0 and later.

Affected products

  • Regular Labs Sourcerer before 16.0.0

Timeline

  • 2026-08-17: disclosed
  • 2026: patched: Fixed in version 16.0.0

References

Related threats