Stored XSS Vulnerability in Joomla Modals Extension by Regular Labs
CVE-2026-85189
7.5HIGH
What is CVE-2026-85189?
The Joomla Modals extension by Regular Labs exhibits a stored Cross-Site Scripting (XSS) vulnerability that affects versions prior to 17.0.0. This issue arises when executable URL schemes are treated as standard modal URLs, allowing malicious actors to inject JavaScript code into the browser context of visitors. This flaw can enable unauthorized script execution, leading to potential data theft or session hijacking without leveraging the extension's Pro JavaScript Events feature.
Affected Version(s)
Modals (Free, Pro) extension for Joomla 4.0.0-16.2.0
