Medium severityNVD Advisory· Published Sep 14, 2026· Updated Sep 14, 2026
CVE-2026-85196
CVE-2026-85196
Description
Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context in which the tag is used. Joomla's string input filter does not make the same value safe for HTML text, an HTML attribute and a URL. A visitor-controlled request value can therefore become an executable URL or a new event attribute in output configured by a site author.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3- Range: < 20.0.0
- Range: < 20.0.0
- Range: < 2.1.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.