VulnSea

regularlabs.com has 9 CVEs on record. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was September 2026 with 9. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report. The most common weakness class is CWE-79 (7). Most affected products: plg_system_articlesanywhere (2), plg_system_modals (2), plg_system_advancedmodules (1).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
9 prev 0

Products

  • plg_system_articlesanywhere 2
  • plg_system_modals 2
  • plg_system_advancedmodules 1
  • plg_system_conditionalcontent 1
  • plg_system_quickindex 1
  • plg_system_snippets 1
9
Total CVEs
1
Critical
0
CISA KEV
0
Exploited

regularlabs.com vulnerabilities

CVEs affecting regularlabs.com, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-85195High· 7.5
1w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover

Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover. In affected versions, those options b…

Twilightregularlabs.com · plg_system_articlesanywhereEPSS 0.25%via NVD
CVE-2026-85192Critical· 9.4
1w ago

Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 - Conditional Content Pro accepts inline PHP Condition Rules in article syntax

Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension for Joomla < 8.0.0 - Conditional Content Pro accepts inline PHP Condition Rules in article syntax. In affected versions…

Midnightregularlabs.com · plg_system_conditionalcontentEPSS 0.48%via NVD
CVE-2026-85188Medium· 6.9
1w ago

Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla - The Conditio…

Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla - The Conditio…

Sunlitregularlabs.com · plg_system_advancedmodulesEPSS 0.22%via NVD
CVE-2026-88852High· 7.5
1w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0 - Snippets substitutes variable values supplied by an article tag into sa…

Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0 - Snippets substitutes variable values supplied by an article tag into sa…

Twilightregularlabs.com · plg_system_snippetsEPSS 0.25%via NVD
CVE-2026-85196Medium· 5.3
1w ago

Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags …

Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags …

Sunlitregularlabs.com · plg_system_articlesanywhereEPSS 0.26%via NVD
CVE-2026-85190High· 7.5
1w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute

Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. A cr…

Twilightregularlabs.com · plg_system_quickindexEPSS 0.25%via NVD
CVE-2026-88853High· 7.5
1w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed

Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed. Affected versions do not…

Twilightregularlabs.com · plg_system_modalsEPSS 0.25%via NVD
CVE-2026-85191High· 7.5
1w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions rewrites links matching an item alias into calls to its browser API

Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions rewrites links matching an item alias into calls to its browser API. The affected rend…

Twilightregularlabs.com · plg_system_tabsEPSS 0.25%via NVD
CVE-2026-85189High· 7.5
1w ago

Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL

Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL. The value can re…

Twilightregularlabs.com · plg_system_modalsEPSS 0.25%via NVD
regularlabs.com vulnerabilities (CVEs) · VulnSea