Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote
CVE-2026-74253CriticalCVSS 10.0CVE published 17 August 2026Added to mySites.guru 17 August 2026

Sourcerer (sourcerer) 12.2.9 to below 16.0.0 - Unauthenticated Remote Code Execution

Regular Labs Sourcerer before 16.0.0 processes {source} blocks found in Joomla's final rendered HTML without reliably determining where that code originated, allowing an unauthenticated visitor to get PHP executed on the site. CVE-2026-74253, CVSS 4.0 10.0 Critical (AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H), CWE-94, credited to Lukasz Rybak. THIS FLAW TOOK THREE ATTEMPTS TO FIX AND IS BEING EXPLOITED IN THE WILD. The vendor first patched it in 14.0.0 (17 August 2026) and the Joomla CNA originally titled the record "Sourcerer < 14.0.0", but that patch was incomplete. 15.0.0 (24 August 2026) reworked the permission model and still did not close it. Only 16.0.0 (26 August 2026) carries the vendor's second [SECURITY FIX] entry: "Prevents unverified Sourcerer code from executing when an untrusted user supplies Sourcerer syntax through URL or form names and values, raw request bodies, uploads, cookies or request headers." The CNA has re-scoped the same CVE id accordingly and its affected range now reads 1.0.0 to 15.0.0, so 14.0.0, 14.0.1 and 15.0.0 are vulnerable despite each having been published as a fix. The Joomla Security Strike Team confirmed on 24 August 2026 that this is being actively exploited in the wild, from around 19 August 2026, which is after the incomplete 14.0.0 patch shipped. UPDATE TO 16.0.0 OR LATER. Updating to 14.x or 15.0.0 is not sufficient. If you cannot update immediately, disable the Sourcerer system plugin, which is the plugin that renders Sourcerer tags. Note that 16.0.0 is deliberately a BC break: it blocks common filesystem-write functions by default and adds them to existing saved settings, so trusted Sourcerer PHP that writes files may stop working, and Pro gains a Trusted Request User Groups setting controlling which logged-in users may submit Sourcerer tags through website requests. Pro builds report their version with a PRO suffix (15.0.0PRO); the matcher strips that suffix before comparison, so this rule is bounded below the fixed version in the normal way and a site on 16.0.0PRO is correctly not flagged.

Is my site affected?

CVE-2026-74253 is checked by 2 rules. Find the extension and release line your site runs:

ExtensionAffected versionsFixed inWhat to do
Sourcererfrom 12.2.9 up to but not including 16.0.016.0.0Update Sourcerer to 16.0.0 for this flaw, or to 16.0.1 or later, which no rule we check matches.
Sourcererup to and including 12.2.8update to 13.0.0Update Sourcerer to 13.0.0 for this flaw, or to 16.0.1 or later, which no rule we check matches.

How CVE-2026-74253 is scored

The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.

10.0 Critical

CVSS 4.0, scored by Joomla CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

How it is reached

AV:N Attack vector
Network. Reachable across the internet
AC:L Attack complexity
Low. Nothing to work around, it just works
AT:N Attack requirements
None. Works against any affected install
PR:N Privileges required
None. No account needed
UI:N User interaction
None. Nobody has to be tricked into anything

What it does to the site

VC:H Confidentiality
High. Everything the site holds can be read
VI:H Integrity
High. Data and files can be altered at will
VA:H Availability
High. The site can be taken down

What it does beyond the site

SC:H Confidentiality
High. Data on other systems can be read
SI:H Integrity
High. Other systems can be altered
SA:H Availability
High. Other systems can be taken down

Timeline

  1. 17 August 2026CVE-2026-74253 record published by its CNA
  2. 17 August 2026mySites.guru check added for Sourcerer (from 12.2.9 up to but not including 16.0.0)

Rule details

Sourcerer - Sourcerer (sourcerer) below 13.0.0 - Code Execution (CVE-2025-22204) and PHP/Script Privilege Escalation

Regular Labs Sourcerer is affected by two lines of security issue. (1) CVE-2025-22204: improper control of code generation leading to code execution in versions before 11.0.0. (2) The coordinated Regular Labs security release of 22 July 2026 (Sourcerer 13.0.0) restricts PHP in articles to content created and last modified by Super Users, enforces the configured CSS/JavaScript/PHP permissions across tags, attributes, files and both article creators and modifiers, restricts PHP includes to the configured include folder, and fixes script/style security checks that missed executable tag variants - collectively a set of privilege-escalation and code/markup-execution hardening fixes. No CVE was assigned to the 22 July issues. Update to Sourcerer 13.0.0 or later. Note: 13.0.0 preserves your existing Pro security settings on update, so review them to opt into the new stricter defaults. CVE ids assigned by the Joomla CNA for this extension in the 22 July 2026 Regular Labs security release: CVE-2026-64796. Sites on this version range are ALSO within the affected range of CVE-2026-74253 (Sourcerer before 16.0.0, CVSS 4.0 10.0 Critical, unauthenticated remote code execution through unverified reflected code, CWE-94, credited to Lukasz Rybak), whose CNA record was re-scoped on 26 August 2026 and now covers 1.0.0 to 15.0.0. Updating to 13.0.0 is therefore no longer sufficient, and neither is 14.x or 15.0.0: the vendor fix for CVE-2026-74253 was incomplete twice and only Sourcerer 16.0.0 (26 August 2026) resolves it. Update to 16.0.0 or later. The Joomla Security Strike Team confirmed active exploitation in the wild from around 19 August 2026. If you cannot update immediately, disable the Sourcerer system plugin, which is the plugin that renders Sourcerer tags.

Affected versions: ≤ 12.2.8

Full advisory: regularlabs.com

Other vulnerabilities in Sourcerer

Updating for CVE-2026-74253 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.

Sourcerer

Latest safe version: 16.0.1

References

CVE-2026-74253 questions

Which versions are affected by CVE-2026-74253?
CVE-2026-74253 is covered by 2 rules: Sourcerer from 12.2.9 up to but not including 16.0.0; Sourcerer up to and including 12.2.8.
How do I fix CVE-2026-74253?
It depends on the extension and release line your site runs. For Sourcerer from 12.2.9 up to but not including 16.0.0: update Sourcerer to 16.0.0 for this flaw, or to 16.0.1 or later, which no rule we check matches. For Sourcerer up to and including 12.2.8: update Sourcerer to 13.0.0 for this flaw, or to 16.0.1 or later, which no rule we check matches.
How severe is CVE-2026-74253?
Joomla CNA scores it 10.0 (Critical) under CVSS 4.0. In plain terms: reachable across the internet, no account needed and nobody has to be tricked into anything.

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

Rules current as of 5 October 2026.