Stored XSS Vulnerability in Tabs & Accordions Extension by Regular Labs
CVE-2026-85191
7.5HIGH
What is CVE-2026-85191?
The Tabs & Accordions extension for Joomla, prior to version 3.1.0, is susceptible to a stored Cross-Site Scripting (XSS) vulnerability. This issue arises from the unvalidated handling of the 'rtla-alias' option, which is injected into an HTML onclick attribute without proper escaping in both JavaScript and HTML contexts. An attacker can exploit this flaw by crafting a malicious 'data-rlta-alias' value, allowing them to manipulate the generated JavaScript handler and potentially execute arbitrary scripts in the context of users' browsers.
Affected Version(s)
Tabs & Accordions (Free, Pro) extension for Joomla 1.0.0-3.0.5
