Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2025-22204CriticalCVSS 9.8CVE published 4 February 2025

Sourcerer (sourcerer) below 13.0.0 - Code Execution (CVE-2025-22204) and PHP/Script Privilege Escalation

Regular Labs Sourcerer is affected by two lines of security issue. (1) CVE-2025-22204: improper control of code generation leading to code execution in versions before 11.0.0. (2) The coordinated Regular Labs security release of 22 July 2026 (Sourcerer 13.0.0) restricts PHP in articles to content created and last modified by Super Users, enforces the configured CSS/JavaScript/PHP permissions across tags, attributes, files and both article creators and modifiers, restricts PHP includes to the configured include folder, and fixes script/style security checks that missed executable tag variants - collectively a set of privilege-escalation and code/markup-execution hardening fixes. No CVE was assigned to the 22 July issues. Update to Sourcerer 13.0.0 or later. Note: 13.0.0 preserves your existing Pro security settings on update, so review them to opt into the new stricter defaults. CVE ids assigned by the Joomla CNA for this extension in the 22 July 2026 Regular Labs security release: CVE-2026-64796. Sites on this version range are ALSO within the affected range of CVE-2026-74253 (Sourcerer before 16.0.0, CVSS 4.0 10.0 Critical, unauthenticated remote code execution through unverified reflected code, CWE-94, credited to Lukasz Rybak), whose CNA record was re-scoped on 26 August 2026 and now covers 1.0.0 to 15.0.0. Updating to 13.0.0 is therefore no longer sufficient, and neither is 14.x or 15.0.0: the vendor fix for CVE-2026-74253 was incomplete twice and only Sourcerer 16.0.0 (26 August 2026) resolves it. Update to 16.0.0 or later. The Joomla Security Strike Team confirmed active exploitation in the wild from around 19 August 2026. If you cannot update immediately, disable the Sourcerer system plugin, which is the plugin that renders Sourcerer tags.

Is my site affected?

Affected
Sourcerer up to and including 12.2.8
Fixed in
Update to 13.0.0 or later
What to do
Update Sourcerer to 13.0.0 for this flaw, or to 16.0.1 or later, which no rule we check matches.

How CVE-2025-22204 is scored

The base metrics as CISA-ADP published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.

9.8 Critical

CVSS 3.1, scored by CISA-ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

How it is reached

AV:N Attack vector
Network. Reachable across the internet
AC:L Attack complexity
Low. Nothing to work around, it just works
PR:N Privileges required
None. No account needed
UI:N User interaction
None. Nobody has to be tricked into anything
S:U Scope
Unchanged. Contained to the extension it is in

What it does

C:H Confidentiality
High. Everything the site holds can be read
I:H Integrity
High. Data and files can be altered at will
A:H Availability
High. The site can be taken down

Timeline

  1. 4 February 2025CVE-2025-22204 record published by its CNA

Rule details

Other vulnerabilities in Sourcerer

Updating for CVE-2025-22204 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.

Sourcerer

Latest safe version: 16.0.1

References

CVE-2025-22204 questions

Which versions are affected by CVE-2025-22204?
CVE-2025-22204 affects Sourcerer up to and including 12.2.8.
How do I fix CVE-2025-22204?
Update Sourcerer to 13.0.0 for this flaw, or to 16.0.1 or later, which no rule we check matches. Then confirm the installed version on the Joomla administrator's Extensions: Manage screen.
How severe is CVE-2025-22204?
CISA-ADP scores it 9.8 (Critical) under CVSS 3.1. In plain terms: reachable across the internet, no account needed and nobody has to be tricked into anything.

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

Rules current as of 5 October 2026.