Junglewise Threat Intelligence

CVE-2026-85196: Regular Labs Articles Anywhere and Users Anywhere reflected XSS

CVE-2026-85196 · Severity: info · Published 2026-09-14

Technologies: Regular Labs Users Anywhere, Regular Labs Articles Anywhere. Vendors: Regular Labs.

Executive brief

Regular Labs produces popular Joomla extensions (Articles Anywhere and Users Anywhere) used by over 100,000 websites to manage content display. These extensions fail to properly sanitize visitor-supplied input before inserting it into HTML, allowing attackers to inject malicious scripts or modify page functionality. An attacker could trick a visitor into clicking a malicious link to steal credentials or take control of their session.

Technical details

This is a reflected cross-site scripting (XSS) vulnerability in the Articles Anywhere and Users Anywhere Joomla extensions. The root cause is that these extensions return request-input data values without context-aware sanitization—Joomla's string filter does not provide the same safety for HTML text, HTML attributes, and URLs. An attacker can craft a malicious URL containing executable script or event attributes that execute in a victim's browser when the extension processes the unsanitized request parameter. The vulnerability is reflected (not stored), so exploitation requires social engineering or URL injection. No special authentication is required.

Affected products

  • Regular Labs Articles Anywhere < 20.0.0
  • Regular Labs Users Anywhere < 2.1.0

Timeline

  • 2026-09-14: disclosed

References

Related threats