Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context in which the tag is used. Joomla's string input filter does not make the same value safe for HTML text, an HTML attribute and a URL. A visitor-controlled request value can therefore become an executable URL or a new event attribute in output configured by a site author.
Metrics
Affected Vendors & Products
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.regularlabs.com/ |
|
History
Mon, 14 Sep 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Regularlabs.com
Regularlabs.com articles Anywhere Pro Extension For Joomla Regularlabs.com users Anywhere Pro Extension For Joomla |
|
| Vendors & Products |
Regularlabs.com
Regularlabs.com articles Anywhere Pro Extension For Joomla Regularlabs.com users Anywhere Pro Extension For Joomla |
Mon, 14 Sep 2026 07:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context in which the tag is used. Joomla's string input filter does not make the same value safe for HTML text, an HTML attribute and a URL. A visitor-controlled request value can therefore become an executable URL or a new event attribute in output configured by a site author. | |
| Title | Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 | |
| Weaknesses | CWE-79 | |
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-09-14T06:21:18.710Z
Reserved: 2026-09-03T12:25:28.491Z
Link: CVE-2026-85196
No data.
Status : Received
Published: 2026-09-14T07:17:23.017
Modified: 2026-09-14T07:17:23.017
Link: CVE-2026-85196
No data.
OpenCVE Enrichment
Updated: 2026-09-14T09:15:17Z
Weaknesses