CVE-2026-64796

CRITICAL

Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension

Title source: cna
STIX 2.1

Description

Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.

References (1)

Core 1
Core References
Product product
https://regularlabs.com/

Scores

CVSS v3 9.8
EPSS 0.0029
EPSS Percentile 20.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

CWE
CWE-284
Status published
Products (1)
regularlabs.com/Sourcerer extension for Joomla 1.0.0-12.2.8
Published Jul 22, 2026
Tracked Since Jul 23, 2026