Stored Cross-Site Scripting Vulnerability in Regular Labs Product
CVE-2026-63281

4.8MEDIUM

What is CVE-2026-63281?

This vulnerability allows an attacker to store malicious HTML or JavaScript in the administrator summaries of Regular Labs extensions. When an administrator views the summary, the embedded code is executed, potentially leading to unauthorized actions or data theft. It's important for users to upgrade their products to mitigate this risk and protect their systems from exploitation.

Affected Version(s)

Advanced Module Manager extension for Joomla 1.0.0-11.0.1

Conditional Content extension for Joomla 1.0.0-6.0.0

Content Templater Pro extension for Joomla 1.0.0-13.0.0

References

CVSS V3.1

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.