XML File Inclusion Vulnerability in ReReplacer by Regular Labs
CVE-2026-65754

7.5HIGH

Key Information:

Vendor
CVE Published:
23 July 2026

What is CVE-2026-65754?

The XML file inclusion vulnerability in ReReplacer allows attackers to leverage misconfigured paths to access sensitive files outside the intended directory. This could lead to unauthorized data exposure, compromising the security of the web application and potentially affecting user data. Regular Labs has issued an update to mitigate this issue, and it is crucial for users to upgrade to the latest version to safeguard their systems.

Affected Version(s)

ReReplacer PRo extension for Joomla 1.0.0-15.0.3

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.