VYPR
Vendor

Regular Labs

Products
17
CVEs
20
Across products
24
Status
Private

Products

17

Recent CVEs

20
  • CVE-2026-74253CriAug 17, 2026
    risk 0.65cvss epss 0.00

    Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 - Regular Labs Sourcerer before 16.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining where that code originated.

  • CVE-2025-22204CriFeb 4, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.

  • CVE-2026-85192CriSep 14, 2026
    risk 0.61cvss epss 0.00

    Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 - Conditional Content Pro accepts inline PHP Condition Rules in article syntax. In affected versions, the PHP is passed to the Conditions…

  • CVE-2026-88852HigSep 14, 2026
    risk 0.49cvss epss 0.00

    Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0 - Snippets substitutes variable values supplied by an article tag into saved Snippet content. The affected versions…

  • CVE-2026-85188MedSep 14, 2026
    risk 0.45cvss epss 0.00

    Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla - The Conditions editor creates a default Condition Set…

  • CVE-2026-65756MedJul 23, 2026
    risk 0.00cvss 6.1epss 0.00

    Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.

  • CVE-2026-64874CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.

  • CVE-2026-64873CriJul 23, 2026
    risk 0.00cvss 9.8epss 0.00

    Joomla Extension - regularlabs.com - SSRF in Cache Cleaner Pro extension - Custom query URLs could access internal or reserved network services.

  • CVE-2026-64872MedJul 23, 2026
    risk 0.00cvss 6.5epss 0.00

    Joomla Extension - regularlabs.com - Path traversal in Cache Cleaner Pro extension - Custom purge and log paths could escape the site webroot directory.

  • CVE-2026-64798CriJul 22, 2026
    risk 0.00cvss 9.1epss 0.00

    Joomla Extension - regularlabs.com - Insecure login URL keys in IP login extension - Persistent URL login keys were also generated using a non-cryptographic random generator with insufficient entropy.

  • CVE-2026-64797HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - regularlabs.com - IP spoofing vulnerability in IP login extension - IP Login trusted forwarded client-IP headers without requiring a configured trusted proxy. Attackers could spoof the IP used for automatic login and potentially impersonate mapped accounts.

  • CVE-2026-64795MedJul 22, 2026
    risk 0.00cvss 5.4epss 0.00

    Joomla Extension - regularlabs.com - XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe markup. A content author could inject JavaScript that…

  • CVE-2026-64794MedJul 22, 2026
    risk 0.00cvss 6.5epss 0.00

    Joomla Extension - regularlabs.com - restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content could expose authentication-related data, raw user…

  • CVE-2026-64792HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - regularlabs.com - disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity instead of a public guest. Restricted or…

  • CVE-2026-64791HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-management and installation permissions. An unauthorized…

  • CVE-2026-63684HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and…

  • CVE-2026-63683HigJul 22, 2026
    risk 0.00cvss 7.5epss 0.00

    Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.

  • CVE-2026-63281MedJul 22, 2026
    risk 0.00cvss 4.8epss 0.00

    Joomla Extension - regularlabs.com - XSS vulnerability in Regular Labs conditions manager - Stored condition values could also execute HTML/JavaScript in administrator summaries.

  • CVE-2026-63280HigJul 22, 2026
    risk 0.00cvss 8.8epss 0.00

    Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions.

  • CVE-2026-63265HigJul 22, 2026
    risk 0.00cvss 8.0epss 0.00

    Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted…