Unauthenticated RCE Vulnerability in Sourcerer by Regular Labs
CVE-2026-74253
10CRITICAL
What is CVE-2026-74253?
The Sourcerer extension by Regular Labs for Joomla prior to version 14.0.0 is susceptible to an unauthenticated remote code execution vulnerability. This occurs when the application processes {source} blocks from rendered HTML without properly verifying the origin of the input, allowing attackers to execute arbitrary code via unverified user input.
Affected Version(s)
Sourcerer extension for Joomla 1.0.0-13.1.1
