CVE-2026-64796
CRITICALJoomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension
Title source: cnaDescription
Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.
References (1)
Core 1
Core References
Product product
https://regularlabs.com/
Scores
CVSS v3
9.8
EPSS
0.0029
EPSS Percentile
20.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
total
Details
CWE
CWE-284
Status
published
Products (1)
regularlabs.com/Sourcerer extension for Joomla
1.0.0-12.2.8
Published
Jul 22, 2026
Tracked Since
Jul 23, 2026