Stored XSS Vulnerability in Joomla Modals Extension by Regular Labs
CVE-2026-85189

7.5HIGH

Key Information:

Vendor
CVE Published:
14 September 2026

What is CVE-2026-85189?

The Joomla Modals extension by Regular Labs exhibits a stored Cross-Site Scripting (XSS) vulnerability that affects versions prior to 17.0.0. This issue arises when executable URL schemes are treated as standard modal URLs, allowing malicious actors to inject JavaScript code into the browser context of visitors. This flaw can enable unauthorized script execution, leading to potential data theft or session hijacking without leveraging the extension's Pro JavaScript Events feature.

Affected Version(s)

Modals (Free, Pro) extension for Joomla 4.0.0-16.2.0

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.