---
id: CVE-2026-85196
title: >-
  Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere
  extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 -
  Articles Anywhere Pro and Users Anywhere Pro return values from request-input
  data tags …
summary: >-
  Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere
  extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 -
  Articles Anywhere Pro and Users Anywhere Pro return values from request-input
  data tags …
severity: medium
cvss: 5.3
cvssVector: 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N'
cwe:
  - CWE-79
vendor: regularlabs.com
product: plg_system_articlesanywhere
affected:
  - plg_system_articlesanywhere 8.4.0-19.0.6
  - plg_system_usersanywhere 1.0.0-2.0.6
published: '2026-09-14'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T19:28:06.713'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85196'
references:
  - url: 'https://www.regularlabs.com/'
    label: security@joomla.org
tags:
  - nvd
  - cve.org
epss: 0.00258
epssPercentile: 0.17728
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-14T11:14:35.863481Z'
cvssSource: cna
ingestedAt: '2026-09-14T15:23:07.460Z'
---

## Overview

Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context in which the tag is used. Joomla's string input filter does not make the same value safe for HTML text, an HTML attribute and a URL. A visitor-controlled request value can therefore become an executable URL or a new event attribute in output configured by a site author.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
