Vendor
Regular Labs vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 38 vulnerabilities in Regular Labs: 0 in the last 7 days and 38 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-88853, was published on 14 September 2026. 11 technologies have a page of their own.
- Last 7 days
- 0
- Last 90 days
- 38
- Critical, all time
- 0
- Exploited in the wild
- 0
About Regular Labs
A developer of extensions and tools for the Joomla content management system.
Regular Labs technologies
- Regular Labs Articles-Anywhere6
- Regular Labs Conditional Content6
- Regular Labs Advanced Module Manager4
- Regular Labs GeoIP4
- Regular Labs Rereplacer-Pro4
- Regular Labs Cache Cleaner Pro3
- Regular Labs Content Templater Pro3
- Regular Labs Modules-Anywhere3
- Regular Labs ReReplacer3
- Regular Labs Sourcerer3
- Regular Labs Users-Anywhere3
Latest Regular Labs vulnerabilities
- CVE-2026-88853: Regular Labs Modals Pro stored XSS via event handlerinfoCVSS 6.3EPSS 0.4%
- CVE-2026-88852: Regular Labs Snippets stored XSS via url optioninfoCVSS 0EPSS 0.4%
- CVE-2026-85196: Regular Labs Articles Anywhere and Users Anywhere reflected XSSinfoEPSS 0.4%
- CVE-2026-85195: Regular Labs Articles Anywhere stored XSS via link optioninfoEPSS 0.4%
- CVE-2026-85192: Regular Labs Conditional Content authenticated remote code execution in JoomlainfoCVSS 7.2EPSS 0.7%
- CVE-2026-85191: Regular Labs Tabs & Accordions stored XSS in rtla-alias optioninfoEPSS 0.4%
- CVE-2026-85190: Regular Labs Quick Index stored XSS via unescaped class attributeinfoEPSS 0.4%
- CVE-2026-85189: Regular Labs Modals stored XSS via executable URL schemesinfoCVSS 5.4EPSS 0.4%
- CVE-2026-85188: Regular Labs Advanced Module Manager database disclosure in Conditions editorinfoEPSS 0.4%
- CVE-2026-74253: Regular Labs Sourcerer RCE in unverified reflected inputinfoEPSS 0.4%
- CVE-2026-65757: Regular Labs Modules Anywhere improper access control in editor popupinfo
- CVE-2026-65756: Regular Labs Keyboard Shortcuts for Joomla XSS in shortcut configurationinfoCVSS 0
- CVE-2026-65755: Regular Labs Joomla extensions information exposure via improper cachinginfo
- CVE-2026-65754: Regular Labs ReReplacer Pro path traversal in XML include pathsinfo
- CVE-2026-65713: Regular Labs Modals Pro path traversal in gallery pathsinfo
- CVE-2026-65712: Regular Labs CDN for Joomla Pro path traversal in CDN versioninginfo
- CVE-2026-65431: Regular Labs GeoIP extension for Joomla path traversal in database updatesinfo
- CVE-2026-65430: Regular Labs GeoIP extension for Joomla credential leakage in request URLsinfoCVSS 0
- CVE-2026-64876: Regular Labs GeoIP extension for Joomla improper access control in database updatesinfoCVSS 0
- CVE-2026-64875: Regular Labs GeoIP extension for Joomla GeoIP-rule bypass via IP spoofinginfoCVSS 0
- CVE-2026-64874: Regular Labs Cache Cleaner Pro credential exposure in request URLsinfoCVSS 0
- CVE-2026-64873: Regular Labs Cache Cleaner Pro SSRF via custom query URLsinfoCVSS 0
- CVE-2026-64872: Regular Labs Cache Cleaner Pro path traversal in custom purge and log pathsinfo
- CVE-2026-64871: Regular Labs Cache Cleaner for Joomla improper access control in URL purgesinfoCVSS 0
- CVE-2026-64799: Regular Labs Joomla extensions SSRF and file write via image URLsinfoCVSS 0
Most severe Regular Labs vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-85192: Regular Labs Conditional Content authenticated remote code execution in JoomlainfoCVSS 7.2EPSS 0.7%
- CVE-2026-88853: Regular Labs Modals Pro stored XSS via event handlerinfoCVSS 6.3EPSS 0.4%
- CVE-2026-85189: Regular Labs Modals stored XSS via executable URL schemesinfoCVSS 5.4EPSS 0.4%
- CVE-2026-88852: Regular Labs Snippets stored XSS via url optioninfoCVSS 0EPSS 0.4%
- CVE-2026-65756: Regular Labs Keyboard Shortcuts for Joomla XSS in shortcut configurationinfoCVSS 0
- CVE-2026-65430: Regular Labs GeoIP extension for Joomla credential leakage in request URLsinfoCVSS 0
- CVE-2026-64876: Regular Labs GeoIP extension for Joomla improper access control in database updatesinfoCVSS 0
- CVE-2026-64875: Regular Labs GeoIP extension for Joomla GeoIP-rule bypass via IP spoofinginfoCVSS 0
- CVE-2026-64874: Regular Labs Cache Cleaner Pro credential exposure in request URLsinfoCVSS 0
- CVE-2026-64873: Regular Labs Cache Cleaner Pro SSRF via custom query URLsinfoCVSS 0
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 0 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 28 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 1 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 9 | 0 | |
| 21 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/vendors/regular-labs.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "Regular Labs vulnerabilities", https://junglewise.ai/threats/vendors/regular-labs, 26 September 2026.