Stored XSS Vulnerability in Tabs & Accordions Extension by Regular Labs
CVE-2026-85191

7.5HIGH

What is CVE-2026-85191?

The Tabs & Accordions extension for Joomla, prior to version 3.1.0, is susceptible to a stored Cross-Site Scripting (XSS) vulnerability. This issue arises from the unvalidated handling of the 'rtla-alias' option, which is injected into an HTML onclick attribute without proper escaping in both JavaScript and HTML contexts. An attacker can exploit this flaw by crafting a malicious 'data-rlta-alias' value, allowing them to manipulate the generated JavaScript handler and potentially execute arbitrary scripts in the context of users' browsers.

Affected Version(s)

Tabs & Accordions (Free, Pro) extension for Joomla 1.0.0-3.0.5

References

CVSS V4

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.