High severityNVD Advisory· Published Sep 14, 2026
CVE-2026-88853
CVE-2026-88853
Description
Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed. Affected versions do not distinguish trusted extension configuration from event code supplied in ordinary article content. A lower-privileged author can therefore use a documented executable feature which should be reserved for trusted authors.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2- Range: <17.0.0
- Range: <17.0.0
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.