Joomla Extension - regularlabs.com - LFI / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla - Modules Anywhere Pro lets additional attributes on a module tag replace arbitrary parameters of the selected module. This feature is enabled by default in affected versions. The overrides are applied without checking who authored the content containing the tag. The security effect depends on how the selected module consumes the replaced parameter. Joomla's core Feed module provides a concrete affected path: its rssurl parameter is opened by the server and accepts local file: URLs as well as network URLs.
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

Mon, 28 Sep 2026 08:45:00 +0000

Type Values Removed Values Added
First Time appeared Regularlabs.com
Regularlabs.com modules Anywhere Pro Extension For Joomla
Vendors & Products Regularlabs.com
Regularlabs.com modules Anywhere Pro Extension For Joomla

Mon, 28 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - regularlabs.com - LFI / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla - Modules Anywhere Pro lets additional attributes on a module tag replace arbitrary parameters of the selected module. This feature is enabled by default in affected versions. The overrides are applied without checking who authored the content containing the tag. The security effect depends on how the selected module consumes the replaced parameter. Joomla's core Feed module provides a concrete affected path: its rssurl parameter is opened by the server and accepts local file: URLs as well as network URLs.
Title Joomla Extension - regularlabs.com - Arbitrary file read / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla
Weaknesses CWE-918
References
Metrics cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-09-28T07:00:40.131Z

Reserved: 2026-09-26T14:17:26.958Z

Link: CVE-2026-100750

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-28T07:17:18.620

Modified: 2026-09-28T07:17:18.620

Link: CVE-2026-100750

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-28T08:30:09Z

Weaknesses