High severityNVD Advisory· Published Sep 14, 2026· Updated Sep 14, 2026
CVE-2026-85190
CVE-2026-85190
Description
Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. A crafted value can close the intended class attribute and introduce a new attribute. Joomla's content filter cannot reliably prevent this because Quick Index creates the executable HTML after the authored plugin syntax was filtered.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <5.0.5
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.