---
id: CVE-2026-85195
title: >-
  Joomla Extension - regularlabs.com - Privileged stored XSS via link option in
  Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts
  link options such as onclick and onmouseover
summary: >-
  Joomla Extension - regularlabs.com - Privileged stored XSS via link option in
  Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts
  link options such as onclick and onmouseover. In affected versions, those
  options b…
severity: high
cvss: 7.5
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N'
cwe:
  - CWE-79
vendor: regularlabs.com
product: plg_system_articlesanywhere
affected:
  - plg_system_articlesanywhere 14.0.0-19.0.6
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:28:06.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85195'
references:
  - url: 'https://www.regularlabs.com/'
    label: security@joomla.org
tags:
  - nvd
  - cve.org
epss: 0.00418
epssPercentile: 0.33427
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T11:10:50.486333Z'
cvssSource: cna
ingestedAt: '2026-09-14T15:23:07.461Z'
---

## Overview

Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover. In affected versions, those options become real HTML event attributes without checking the article author's trust level. The plugin syntax survives Joomla's normal Author content filter because the executable HTML is generated later.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
