Critical severityNVD Advisory· Published Sep 14, 2026· Updated Sep 14, 2026
CVE-2026-85192
CVE-2026-85192
Description
Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 - Conditional Content Pro accepts inline PHP Condition Rules in article syntax. In affected versions, the PHP is passed to the Conditions evaluator without checking who authored the article. Joomla's normal Author text filter preserves the syntax, so publishing the article causes the code to run as the web-server process.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <8.0.0
- Range: <8.0.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.