<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>mySites.guru Joomla Vulnerability Database</title><description>New Joomla extension vulnerability rules as mySites.guru starts checking connected sites against them.</description><link>https://mysites.guru/</link><language>en-gb</language><atom:link rel="self" type="application/rss+xml" href="https://mysites.guru/vulnerabilities/rss.xml"/><image><url>https://mysites.guru/favicon.svg</url><title>mySites.guru Joomla Vulnerability Database</title><link>https://mysites.guru/vulnerabilities/</link></image><item><title>Tabs &amp; Accordions (tabsaccordions) 3.0.0 to below 3.1.0 - Authenticated Stored XSS via Crafted data-rlta-alias Attributes</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85191/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-467</guid><description>Regular Labs Tabs &amp; Accordions 3.0.0 through 3.0.5 is affected by CVE-2026-85191, fixed in 3.1.0 (released 13 September 2026). Crafted data-rlta-alias attributes were not sanitised, so JavaScript ran when a matching link was clicked. Exploitation requires the ability to author or edit content containing a Tabs &amp; Accordions link, so this is an authenticated stored XSS that fires on visitor interaction rather than on page load. Update to 3.1.0 or later. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Tabs &amp; Accordions</category><category>Medium</category><category>CVE-2026-85191</category></item><item><title>Tabs &amp; Accordions (tabsaccordions) 3.0.0 to below 3.1.0 - Authenticated Stored XSS via Crafted data-rlta-alias Attributes</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85191/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-466</guid><description>Regular Labs Tabs &amp; Accordions 3.0.0 through 3.0.5 is affected by CVE-2026-85191, fixed in 3.1.0 (released 13 September 2026). Crafted data-rlta-alias attributes were not sanitised, so JavaScript ran when a matching link was clicked. Exploitation requires the ability to author or edit content containing a Tabs &amp; Accordions link, so this is an authenticated stored XSS that fires on visitor interaction rather than on page load. Update to 3.1.0 or later. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Tabs &amp; Accordions</category><category>Medium</category><category>CVE-2026-85191</category></item><item><title>Tabs &amp; Accordions (tabsaccordions) 3.0.0 to below 3.1.0 - Authenticated Stored XSS via Crafted data-rlta-alias Attributes</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85191/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-465</guid><description>Regular Labs Tabs &amp; Accordions 3.0.0 through 3.0.5 is affected by CVE-2026-85191, fixed in 3.1.0 (released 13 September 2026). Crafted data-rlta-alias attributes were not sanitised, so JavaScript ran when a matching link was clicked. Exploitation requires the ability to author or edit content containing a Tabs &amp; Accordions link, so this is an authenticated stored XSS that fires on visitor interaction rather than on page load. Update to 3.1.0 or later. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Tabs &amp; Accordions</category><category>Medium</category><category>CVE-2026-85191</category></item><item><title>Conditional Content (conditionalcontent) 7.0.0 to below 8.0.0 - Authenticated PHP Code Execution via Inline Condition Rules</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85192/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-464</guid><description>Regular Labs Conditional Content 7.0.0 through 7.1.0 is affected by two vendor-confirmed security defects, both fixed in 8.0.0 (released 13 September 2026). CVE-2026-85192 is the more serious and the most serious item in the whole 13 September batch: untrusted article authors could run PHP through inline Condition Rules. That is arbitrary code execution reachable by the lowest content-authoring role on a Joomla site, which on any site permitting self-registration with authoring rights means an attacker can create that account themselves. 8.0.0 restricts it and is flagged by the vendor as a BC BREAK, so sites legitimately using PHP in Condition Rules must re-authorise the author groups allowed to do so. CVE-2026-85188 is a shared-code defect: the same Condition Set implementation ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. Update to 8.0.0 or later and review who holds content-authoring rights. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Conditional Content</category><category>High</category><category>CVE-2026-85192</category><category>CVE-2026-85188</category></item><item><title>Conditional Content (conditionalcontent) 7.0.0 to below 8.0.0 - Authenticated PHP Code Execution via Inline Condition Rules</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85192/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-463</guid><description>Regular Labs Conditional Content 7.0.0 through 7.1.0 is affected by two vendor-confirmed security defects, both fixed in 8.0.0 (released 13 September 2026). CVE-2026-85192 is the more serious and the most serious item in the whole 13 September batch: untrusted article authors could run PHP through inline Condition Rules. That is arbitrary code execution reachable by the lowest content-authoring role on a Joomla site, which on any site permitting self-registration with authoring rights means an attacker can create that account themselves. 8.0.0 restricts it and is flagged by the vendor as a BC BREAK, so sites legitimately using PHP in Condition Rules must re-authorise the author groups allowed to do so. CVE-2026-85188 is a shared-code defect: the same Condition Set implementation ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. Update to 8.0.0 or later and review who holds content-authoring rights. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Conditional Content</category><category>High</category><category>CVE-2026-85192</category><category>CVE-2026-85188</category></item><item><title>Conditional Content (conditionalcontent) 7.0.0 to below 8.0.0 - Authenticated PHP Code Execution via Inline Condition Rules</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85192/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-462</guid><description>Regular Labs Conditional Content 7.0.0 through 7.1.0 is affected by two vendor-confirmed security defects, both fixed in 8.0.0 (released 13 September 2026). CVE-2026-85192 is the more serious and the most serious item in the whole 13 September batch: untrusted article authors could run PHP through inline Condition Rules. That is arbitrary code execution reachable by the lowest content-authoring role on a Joomla site, which on any site permitting self-registration with authoring rights means an attacker can create that account themselves. 8.0.0 restricts it and is flagged by the vendor as a BC BREAK, so sites legitimately using PHP in Condition Rules must re-authorise the author groups allowed to do so. CVE-2026-85188 is a shared-code defect: the same Condition Set implementation ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. Update to 8.0.0 or later and review who holds content-authoring rights. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Conditional Content</category><category>High</category><category>CVE-2026-85192</category><category>CVE-2026-85188</category></item><item><title>Advanced Module Manager (advancedmodules) 12.0.0 to below 12.1.0 - Authenticated Information Disclosure via Condition Set Labels</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85188/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-461</guid><description>Regular Labs Advanced Module Manager 12.0.0 through 12.0.4 is affected by CVE-2026-85188, fixed in 12.1.0 (released 13 September 2026). CVE-2026-85188 is a shared-code defect: the same Condition Set implementation ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. The same release also adds settings restricting who may save PHP Condition Rules. Update to 12.1.0 or later. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Advanced Module Manager</category><category>Medium</category><category>CVE-2026-85188</category></item><item><title>Advanced Module Manager (advancedmodules) 12.0.0 to below 12.1.0 - Authenticated Information Disclosure via Condition Set Labels</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85188/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-460</guid><description>Regular Labs Advanced Module Manager 12.0.0 through 12.0.4 is affected by CVE-2026-85188, fixed in 12.1.0 (released 13 September 2026). CVE-2026-85188 is a shared-code defect: the same Condition Set implementation ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. The same release also adds settings restricting who may save PHP Condition Rules. Update to 12.1.0 or later. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Advanced Module Manager</category><category>Medium</category><category>CVE-2026-85188</category></item><item><title>Advanced Module Manager (advancedmodules) 12.0.0 to below 12.1.0 - Authenticated Information Disclosure via Condition Set Labels</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85188/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-459</guid><description>Regular Labs Advanced Module Manager 12.0.0 through 12.0.4 is affected by CVE-2026-85188, fixed in 12.1.0 (released 13 September 2026). CVE-2026-85188 is a shared-code defect: the same Condition Set implementation ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. The same release also adds settings restricting who may save PHP Condition Rules. Update to 12.1.0 or later. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Advanced Module Manager</category><category>Medium</category><category>CVE-2026-85188</category></item><item><title>Advanced Module Manager (advancedmodules) 12.0.0 to below 12.1.0 - Authenticated Information Disclosure via Condition Set Labels</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85188/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-458</guid><description>Regular Labs Advanced Module Manager 12.0.0 through 12.0.4 is affected by CVE-2026-85188, fixed in 12.1.0 (released 13 September 2026). CVE-2026-85188 is a shared-code defect: the same Condition Set implementation ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. The same release also adds settings restricting who may save PHP Condition Rules. Update to 12.1.0 or later. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Advanced Module Manager</category><category>Medium</category><category>CVE-2026-85188</category></item><item><title>ReReplacer (rereplacer) 16.0.0 to below 16.2.0 - Authenticated Information Disclosure via Condition Set Labels</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85188/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-457</guid><description>Regular Labs ReReplacer 16.0.0 through 16.1.0 is affected by CVE-2026-85188, fixed in 16.2.0 (released 13 September 2026). Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. The same Condition Set code ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. Update to 16.2.0 or later. The same release also adds settings restricting who may save PHP Condition Rules, and fixes Condition Set saves not respecting publication and linked-item edit permissions. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>ReReplacer</category><category>Medium</category><category>CVE-2026-85188</category></item><item><title>ReReplacer (rereplacer) 16.0.0 to below 16.2.0 - Authenticated Information Disclosure via Condition Set Labels</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85188/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-456</guid><description>Regular Labs ReReplacer 16.0.0 through 16.1.0 is affected by CVE-2026-85188, fixed in 16.2.0 (released 13 September 2026). Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. The same Condition Set code ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. Update to 16.2.0 or later. The same release also adds settings restricting who may save PHP Condition Rules, and fixes Condition Set saves not respecting publication and linked-item edit permissions. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>ReReplacer</category><category>Medium</category><category>CVE-2026-85188</category></item><item><title>ReReplacer (rereplacer) 16.0.0 to below 16.2.0 - Authenticated Information Disclosure via Condition Set Labels</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85188/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-455</guid><description>Regular Labs ReReplacer 16.0.0 through 16.1.0 is affected by CVE-2026-85188, fixed in 16.2.0 (released 13 September 2026). Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. The same Condition Set code ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. Update to 16.2.0 or later. The same release also adds settings restricting who may save PHP Condition Rules, and fixes Condition Set saves not respecting publication and linked-item edit permissions. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>ReReplacer</category><category>Medium</category><category>CVE-2026-85188</category></item><item><title>ReReplacer (rereplacer) 16.0.0 to below 16.2.0 - Authenticated Information Disclosure via Condition Set Labels</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85188/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-454</guid><description>Regular Labs ReReplacer 16.0.0 through 16.1.0 is affected by CVE-2026-85188, fixed in 16.2.0 (released 13 September 2026). Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. The same Condition Set code ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. Update to 16.2.0 or later. The same release also adds settings restricting who may save PHP Condition Rules, and fixes Condition Set saves not respecting publication and linked-item edit permissions. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>ReReplacer</category><category>Medium</category><category>CVE-2026-85188</category></item><item><title>Content Templater (contenttemplater) 14.0.0 to below 14.2.0 - Authenticated Information Disclosure via Condition Set Labels</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85188/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-453</guid><description>Regular Labs Content Templater 14.0.0 through 14.1.0 is affected by CVE-2026-85188, fixed in 14.2.0 (released 13 September 2026). Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. The same Condition Set code ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. Update to 14.2.0 or later. The same release also adds settings restricting who may save PHP Condition Rules, and fixes Condition Set saves not respecting publication and linked-item edit permissions. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Content Templater</category><category>Medium</category><category>CVE-2026-85188</category></item><item><title>Content Templater (contenttemplater) 14.0.0 to below 14.2.0 - Authenticated Information Disclosure via Condition Set Labels</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85188/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-452</guid><description>Regular Labs Content Templater 14.0.0 through 14.1.0 is affected by CVE-2026-85188, fixed in 14.2.0 (released 13 September 2026). Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. The same Condition Set code ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. Update to 14.2.0 or later. The same release also adds settings restricting who may save PHP Condition Rules, and fixes Condition Set saves not respecting publication and linked-item edit permissions. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Content Templater</category><category>Medium</category><category>CVE-2026-85188</category></item><item><title>Content Templater (contenttemplater) 14.0.0 to below 14.2.0 - Authenticated Information Disclosure via Condition Set Labels</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85188/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-451</guid><description>Regular Labs Content Templater 14.0.0 through 14.1.0 is affected by CVE-2026-85188, fixed in 14.2.0 (released 13 September 2026). Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. The same Condition Set code ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. Update to 14.2.0 or later. The same release also adds settings restricting who may save PHP Condition Rules, and fixes Condition Set saves not respecting publication and linked-item edit permissions. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Content Templater</category><category>Medium</category><category>CVE-2026-85188</category></item><item><title>Content Templater (contenttemplater) 14.0.0 to below 14.2.0 - Authenticated Information Disclosure via Condition Set Labels</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85188/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-450</guid><description>Regular Labs Content Templater 14.0.0 through 14.1.0 is affected by CVE-2026-85188, fixed in 14.2.0 (released 13 September 2026). Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. The same Condition Set code ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. Update to 14.2.0 or later. The same release also adds settings restricting who may save PHP Condition Rules, and fixes Condition Set saves not respecting publication and linked-item edit permissions. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Content Templater</category><category>Medium</category><category>CVE-2026-85188</category></item><item><title>Content Templater (contenttemplater) 14.0.0 to below 14.2.0 - Authenticated Information Disclosure via Condition Set Labels</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85188/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-449</guid><description>Regular Labs Content Templater 14.0.0 through 14.1.0 is affected by CVE-2026-85188, fixed in 14.2.0 (released 13 September 2026). Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. The same Condition Set code ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. Update to 14.2.0 or later. The same release also adds settings restricting who may save PHP Condition Rules, and fixes Condition Set saves not respecting publication and linked-item edit permissions. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Content Templater</category><category>Medium</category><category>CVE-2026-85188</category></item><item><title>Quick Index (quickindex) 5.0.0 to below 5.0.5 - Authenticated Stored XSS via Crafted Index Class Options</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85190/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-448</guid><description>Regular Labs Quick Index 5.0.0 through 5.0.4 is affected by CVE-2026-85190, fixed in 5.0.5 (released 13 September 2026). Crafted index class options were not sanitised, allowing JavaScript to be injected into the rendered index. Exploitation requires the ability to author or edit content containing a Quick Index tag, so this is an authenticated stored XSS. Update to 5.0.5 or later. The same release also fixes indexes showing headings from articles the visitor cannot access, an access control defect the vendor did not label a security fix but which discloses restricted article titles to unauthorised visitors. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Quick Index</category><category>Medium</category><category>CVE-2026-85190</category></item><item><title>Quick Index (quickindex) 5.0.0 to below 5.0.5 - Authenticated Stored XSS via Crafted Index Class Options</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85190/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-447</guid><description>Regular Labs Quick Index 5.0.0 through 5.0.4 is affected by CVE-2026-85190, fixed in 5.0.5 (released 13 September 2026). Crafted index class options were not sanitised, allowing JavaScript to be injected into the rendered index. Exploitation requires the ability to author or edit content containing a Quick Index tag, so this is an authenticated stored XSS. Update to 5.0.5 or later. The same release also fixes indexes showing headings from articles the visitor cannot access, an access control defect the vendor did not label a security fix but which discloses restricted article titles to unauthorised visitors. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Quick Index</category><category>Medium</category><category>CVE-2026-85190</category></item><item><title>Snippets (snippets) 10.0.0 to below 11.0.0 - Authenticated Stored XSS via Snippet Variable Overrides</title><link>https://mysites.guru/vulnerabilities/CVE-2026-88852/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-446</guid><description>Regular Labs Snippets 10.0.0 through 10.0.6 is affected by CVE-2026-88852, fixed in 11.0.0 (released 13 September 2026). Snippet variable overrides could be set by any user able to author content, letting a lower-privileged author change the values a snippet renders and inject script through them. 11.0.0 restricts variable overrides to selected article author groups by default. Exploitation requires the ability to author or edit content containing Snippets tags, so this is an authenticated stored XSS. Update to 11.0.0 or later. Note that 11.0.0 is flagged by the vendor as a BC BREAK: the restriction is enabled by default and has to be re-opened deliberately per author group, so any site relying on variable overrides should review those settings after updating. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Snippets</category><category>Medium</category><category>CVE-2026-88852</category></item><item><title>Snippets (snippets) 10.0.0 to below 11.0.0 - Authenticated Stored XSS via Snippet Variable Overrides</title><link>https://mysites.guru/vulnerabilities/CVE-2026-88852/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-445</guid><description>Regular Labs Snippets 10.0.0 through 10.0.6 is affected by CVE-2026-88852, fixed in 11.0.0 (released 13 September 2026). Snippet variable overrides could be set by any user able to author content, letting a lower-privileged author change the values a snippet renders and inject script through them. 11.0.0 restricts variable overrides to selected article author groups by default. Exploitation requires the ability to author or edit content containing Snippets tags, so this is an authenticated stored XSS. Update to 11.0.0 or later. Note that 11.0.0 is flagged by the vendor as a BC BREAK: the restriction is enabled by default and has to be re-opened deliberately per author group, so any site relying on variable overrides should review those settings after updating. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Snippets</category><category>Medium</category><category>CVE-2026-88852</category></item><item><title>Snippets (snippets) 10.0.0 to below 11.0.0 - Authenticated Stored XSS via Snippet Variable Overrides</title><link>https://mysites.guru/vulnerabilities/CVE-2026-88852/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-444</guid><description>Regular Labs Snippets 10.0.0 through 10.0.6 is affected by CVE-2026-88852, fixed in 11.0.0 (released 13 September 2026). Snippet variable overrides could be set by any user able to author content, letting a lower-privileged author change the values a snippet renders and inject script through them. 11.0.0 restricts variable overrides to selected article author groups by default. Exploitation requires the ability to author or edit content containing Snippets tags, so this is an authenticated stored XSS. Update to 11.0.0 or later. Note that 11.0.0 is flagged by the vendor as a BC BREAK: the restriction is enabled by default and has to be re-opened deliberately per author group, so any site relying on variable overrides should review those settings after updating. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Snippets</category><category>Medium</category><category>CVE-2026-88852</category></item><item><title>Snippets (snippets) 10.0.0 to below 11.0.0 - Authenticated Stored XSS via Snippet Variable Overrides</title><link>https://mysites.guru/vulnerabilities/CVE-2026-88852/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-443</guid><description>Regular Labs Snippets 10.0.0 through 10.0.6 is affected by CVE-2026-88852, fixed in 11.0.0 (released 13 September 2026). Snippet variable overrides could be set by any user able to author content, letting a lower-privileged author change the values a snippet renders and inject script through them. 11.0.0 restricts variable overrides to selected article author groups by default. Exploitation requires the ability to author or edit content containing Snippets tags, so this is an authenticated stored XSS. Update to 11.0.0 or later. Note that 11.0.0 is flagged by the vendor as a BC BREAK: the restriction is enabled by default and has to be re-opened deliberately per author group, so any site relying on variable overrides should review those settings after updating. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Snippets</category><category>Medium</category><category>CVE-2026-88852</category></item><item><title>Snippets (snippets) 10.0.0 to below 11.0.0 - Authenticated Stored XSS via Snippet Variable Overrides</title><link>https://mysites.guru/vulnerabilities/CVE-2026-88852/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-442</guid><description>Regular Labs Snippets 10.0.0 through 10.0.6 is affected by CVE-2026-88852, fixed in 11.0.0 (released 13 September 2026). Snippet variable overrides could be set by any user able to author content, letting a lower-privileged author change the values a snippet renders and inject script through them. 11.0.0 restricts variable overrides to selected article author groups by default. Exploitation requires the ability to author or edit content containing Snippets tags, so this is an authenticated stored XSS. Update to 11.0.0 or later. Note that 11.0.0 is flagged by the vendor as a BC BREAK: the restriction is enabled by default and has to be re-opened deliberately per author group, so any site relying on variable overrides should review those settings after updating. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Snippets</category><category>Medium</category><category>CVE-2026-88852</category></item><item><title>Modals (modals) 16.0.0 to below 17.0.0 - Authenticated Stored XSS via JavaScript URLs and JavaScript Events</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85189/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-441</guid><description>Regular Labs Modals 16.0.0 through 16.2.0 is affected by two vendor-confirmed security defects, both fixed in 17.0.0 (released 13 September 2026). CVE-2026-85189: modal links accepted javascript: URLs, so a crafted link executed script when the modal was opened. CVE-2026-88853: JavaScript Events could be attached by any user able to author content; 17.0.0 restricts them to selected article author groups by default. Both require the ability to author or edit content containing Modals links or tags, making this an authenticated stored XSS. Update to 17.0.0 or later. Note that 17.0.0 is flagged by the vendor as a BC BREAK: the JavaScript Events restriction is enabled by default and has to be re-opened deliberately per author group, so review those settings after updating. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Modals</category><category>High</category><category>CVE-2026-85189</category><category>CVE-2026-88853</category></item><item><title>Modals (modals) 16.0.0 to below 17.0.0 - Authenticated Stored XSS via JavaScript URLs and JavaScript Events</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85189/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-440</guid><description>Regular Labs Modals 16.0.0 through 16.2.0 is affected by two vendor-confirmed security defects, both fixed in 17.0.0 (released 13 September 2026). CVE-2026-85189: modal links accepted javascript: URLs, so a crafted link executed script when the modal was opened. CVE-2026-88853: JavaScript Events could be attached by any user able to author content; 17.0.0 restricts them to selected article author groups by default. Both require the ability to author or edit content containing Modals links or tags, making this an authenticated stored XSS. Update to 17.0.0 or later. Note that 17.0.0 is flagged by the vendor as a BC BREAK: the JavaScript Events restriction is enabled by default and has to be re-opened deliberately per author group, so review those settings after updating. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Modals</category><category>High</category><category>CVE-2026-85189</category><category>CVE-2026-88853</category></item><item><title>Modals (modals) 16.0.0 to below 17.0.0 - Authenticated Stored XSS via JavaScript URLs and JavaScript Events</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85189/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-439</guid><description>Regular Labs Modals 16.0.0 through 16.2.0 is affected by two vendor-confirmed security defects, both fixed in 17.0.0 (released 13 September 2026). CVE-2026-85189: modal links accepted javascript: URLs, so a crafted link executed script when the modal was opened. CVE-2026-88853: JavaScript Events could be attached by any user able to author content; 17.0.0 restricts them to selected article author groups by default. Both require the ability to author or edit content containing Modals links or tags, making this an authenticated stored XSS. Update to 17.0.0 or later. Note that 17.0.0 is flagged by the vendor as a BC BREAK: the JavaScript Events restriction is enabled by default and has to be re-opened deliberately per author group, so review those settings after updating. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Modals</category><category>High</category><category>CVE-2026-85189</category><category>CVE-2026-88853</category></item><item><title>Users Anywhere (usersanywhere) 2.0.0 to below 2.1.0 - Authenticated Stored and Reflected XSS via Unescaped Request Input</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85196/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-438</guid><description>Regular Labs Users Anywhere 2.0.0 through 2.0.6 is affected by CVE-2026-85196, fixed in 2.1.0 (released 13 September 2026). Request input consumed by Users Anywhere data tags was not escaped, and the optional raw output mode was available to any article author, allowing script to be injected into rendered content. This is the same defect and the same CVE the vendor fixed in Articles Anywhere 20.0.0, the two extensions sharing the data-tag code. Exploitation requires the ability to author or edit content containing Users Anywhere tags, or a page that already feeds request input into one. Update to 2.1.0 or later. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Users Anywhere</category><category>High</category><category>CVE-2026-85196</category></item><item><title>Users Anywhere (usersanywhere) 2.0.0 to below 2.1.0 - Authenticated Stored and Reflected XSS via Unescaped Request Input</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85196/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-437</guid><description>Regular Labs Users Anywhere 2.0.0 through 2.0.6 is affected by CVE-2026-85196, fixed in 2.1.0 (released 13 September 2026). Request input consumed by Users Anywhere data tags was not escaped, and the optional raw output mode was available to any article author, allowing script to be injected into rendered content. This is the same defect and the same CVE the vendor fixed in Articles Anywhere 20.0.0, the two extensions sharing the data-tag code. Exploitation requires the ability to author or edit content containing Users Anywhere tags, or a page that already feeds request input into one. Update to 2.1.0 or later. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Users Anywhere</category><category>High</category><category>CVE-2026-85196</category></item><item><title>Articles Anywhere (articlesanywhere) 19.0.0 to below 20.0.0 - Authenticated Stored and Reflected XSS via Unescaped Request Input and JavaScript Events</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85195/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-436</guid><description>Regular Labs Articles Anywhere 19.0.0 through 19.0.6 is affected by two vendor-confirmed security defects, both fixed in 20.0.0 (released 13 September 2026). CVE-2026-85196: request input consumed by Articles Anywhere data tags was not escaped, and the optional raw output mode was available to any article author, allowing script to be injected into rendered article content. CVE-2026-85195: JavaScript Events could be attached by any user able to author article content; 20.0.0 restricts them to selected article author groups by default. Exploitation requires the ability to author or edit content containing Articles Anywhere tags, or a page that already feeds request input into one, so this is an authenticated stored XSS with a reflected vector on affected pages. Update to 20.0.0 or later. Note that 20.0.0 is flagged by the vendor as a BC BREAK: the JavaScript Events restriction is enabled by default and has to be re-opened deliberately per author group, so review those settings after updating. The same release also tightens destination checks for external image downloads, which the vendor did not label a security fix. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Articles Anywhere</category><category>High</category><category>CVE-2026-85195</category><category>CVE-2026-85196</category></item><item><title>Articles Anywhere (articlesanywhere) 19.0.0 to below 20.0.0 - Authenticated Stored and Reflected XSS via Unescaped Request Input and JavaScript Events</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85195/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-435</guid><description>Regular Labs Articles Anywhere 19.0.0 through 19.0.6 is affected by two vendor-confirmed security defects, both fixed in 20.0.0 (released 13 September 2026). CVE-2026-85196: request input consumed by Articles Anywhere data tags was not escaped, and the optional raw output mode was available to any article author, allowing script to be injected into rendered article content. CVE-2026-85195: JavaScript Events could be attached by any user able to author article content; 20.0.0 restricts them to selected article author groups by default. Exploitation requires the ability to author or edit content containing Articles Anywhere tags, or a page that already feeds request input into one, so this is an authenticated stored XSS with a reflected vector on affected pages. Update to 20.0.0 or later. Note that 20.0.0 is flagged by the vendor as a BC BREAK: the JavaScript Events restriction is enabled by default and has to be re-opened deliberately per author group, so review those settings after updating. The same release also tightens destination checks for external image downloads, which the vendor did not label a security fix. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Articles Anywhere</category><category>High</category><category>CVE-2026-85195</category><category>CVE-2026-85196</category></item><item><title>Articles Anywhere (articlesanywhere) 19.0.0 to below 20.0.0 - Authenticated Stored and Reflected XSS via Unescaped Request Input and JavaScript Events</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85195/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-434</guid><description>Regular Labs Articles Anywhere 19.0.0 through 19.0.6 is affected by two vendor-confirmed security defects, both fixed in 20.0.0 (released 13 September 2026). CVE-2026-85196: request input consumed by Articles Anywhere data tags was not escaped, and the optional raw output mode was available to any article author, allowing script to be injected into rendered article content. CVE-2026-85195: JavaScript Events could be attached by any user able to author article content; 20.0.0 restricts them to selected article author groups by default. Exploitation requires the ability to author or edit content containing Articles Anywhere tags, or a page that already feeds request input into one, so this is an authenticated stored XSS with a reflected vector on affected pages. Update to 20.0.0 or later. Note that 20.0.0 is flagged by the vendor as a BC BREAK: the JavaScript Events restriction is enabled by default and has to be re-opened deliberately per author group, so review those settings after updating. The same release also tightens destination checks for external image downloads, which the vendor did not label a security fix. As at 13 September 2026 the CVE record(s) for this advisory are RESERVED and not yet published, so no official CVSS score exists yet and the severity recorded here is mySites.guru&apos;s own assessment, to be revised when the records go live.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Articles Anywhere</category><category>High</category><category>CVE-2026-85195</category><category>CVE-2026-85196</category></item><item><title>DPCases (com_dpcases) below 3.8.1 - Authenticated Stored XSS and Path Traversal</title><link>https://mysites.guru/vulnerabilities/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-433</guid><description>DPCases before 3.8.1 writes user information into its views without escaping it, so a stored value containing markup becomes live HTML for whoever views the page afterwards. The release also stops icon paths resolving outside the root directory. Update to 3.8.1. No CVE has been assigned at the time of writing; the vendor rates the escaping issue High.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>DPCases</category><category>High</category></item><item><title>DPCases (com_dpcases) below 3.8.1 - Authenticated Stored XSS and Path Traversal</title><link>https://mysites.guru/vulnerabilities/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-432</guid><description>DPCases before 3.8.1 writes user information into its views without escaping it, so a stored value containing markup becomes live HTML for whoever views the page afterwards. The release also stops icon paths resolving outside the root directory. Update to 3.8.1. No CVE has been assigned at the time of writing; the vendor rates the escaping issue High.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>DPCases</category><category>High</category></item><item><title>DPMedia below 1.21.1 - Media Reference Disclosure, Path Traversal and OAuth CSRF</title><link>https://mysites.guru/vulnerabilities/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-431</guid><description>DPMedia before 1.21.1 shows DPReferences entries to users who have no access to the media manager, disclosing which media items exist and where they are used. The release also normalises external file names so a path containing dot segments cannot resolve outside the local cache root, adds a state parameter to the OAuth callback for Google and Dropbox account imports, and fixes an injection in Google Drive search. Update to 1.21.1. No CVE has been assigned at the time of writing; the vendor rates the DPReferences disclosure High.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>DPMedia</category><category>High</category></item><item><title>DPMedia below 1.21.1 - Media Reference Disclosure, Path Traversal and OAuth CSRF</title><link>https://mysites.guru/vulnerabilities/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-430</guid><description>DPMedia before 1.21.1 shows DPReferences entries to users who have no access to the media manager, disclosing which media items exist and where they are used. The release also normalises external file names so a path containing dot segments cannot resolve outside the local cache root, adds a state parameter to the OAuth callback for Google and Dropbox account imports so a forged request cannot complete an account connection, and fixes an injection in Google Drive search. The same commit also constrains the post-OAuth redirect target, which was previously taken from a cookie without validation. Update to 1.21.1. DPMedia ships no component, so this rule matches the library; a sibling rule matches the package. No CVE has been assigned at the time of writing; the vendor rates the DPReferences disclosure High.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>DPMedia</category><category>High</category></item><item><title>DPAttachments (com_dpattachments) below 5.8.1 - Unauthenticated Attachment Download, Stored XSS and Path Traversal</title><link>https://mysites.guru/vulnerabilities/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-429</guid><description>DPAttachments before 5.8.1 exposes every attachment to anyone who can guess an id. The front-end download route confirmed only that an attachment record existed and never checked whether the requester was entitled to it, so unpublished attachments, attachments on a restricted view level, and attachments outside their publish window were all downloadable with no login. Attachment ids are sequential integers. 5.8.1 adds a canView() check enforcing edit permission, published state, view access level and the publish up/down window. The release also fixes a stored cross-site scripting flaw in the CSV preview and adds validation of the upload context string used to build a filesystem path. Update to 5.8.1. No CVE has been assigned at the time of writing; the vendor rates the download flaw High.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>DPAttachments</category><category>High</category></item><item><title>DPAttachments (com_dpattachments) below 5.8.1 - Unauthenticated Attachment Download, Stored XSS and Path Traversal</title><link>https://mysites.guru/vulnerabilities/dpattachments/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-428</guid><description>DPAttachments before 5.8.1 exposes every attachment to anyone who can guess an id. The front-end download route (index.php?option=com_dpattachments&amp;task=attachment.download&amp;id=N) confirmed only that an attachment record existed and never checked whether the requester was entitled to it, so unpublished attachments, attachments on a restricted view level, and attachments outside their publish window were all downloadable with no login. Attachment ids are sequential integers. The same gap was present on the attachment detail view. 5.8.1 adds a canView() check enforcing edit permission, published state, view access level and the publish up/down window on both paths. The release also fixes a stored cross-site scripting flaw in the CSV preview, where the header row was written out unescaped while the data cells were already escaped, and adds validation of the upload context string, which was used to build a filesystem path and could be tampered with to traverse outside it. Update to 5.8.1. No CVE has been assigned at the time of writing; the vendor rates the download flaw High.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>DPAttachments</category><category>High</category></item><item><title>SP Property Finder (com_spproperty) below 4.1.4 - Unauthenticated SQL Injection (full database read) and Mail Relay</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78082/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-255</guid><description>SP Property Finder below 4.1.4 contains an unauthenticated blind SQL injection in the public property search and map views, found by mySites.guru and reported privately to JoomShaper on 10 August 2026. Several search filters (the postcode, the sort control, and the price and size range dropdowns) are placed straight into the database query with no quoting, so an anonymous visitor with no login and no token can read any table in the Joomla database, password hashes and the site secret included. The injection is read-only, but reading the session table lets an attacker steal a logged-in administrator&apos;s session and take over the site from there, so treat it as serious. A second, lower-severity issue let the property contact and enquiry forms send email to any recipient with a spoofed sender (an unauthenticated mail relay). JoomShaper fixed both in SP Property Finder 4.1.4, released on 10 September 2026, which quotes and casts every filter value, validates the sort control against an allow-list, and derives the mail recipient from a database lookup instead of the request. mySites.guru verified the fix against the build JoomShaper shipped as 4.1.4. The same release also fixed further issues that mySites.guru did not report, tracked as CVE-2026-78084, CVE-2026-78302 and CVE-2026-78303. The reporter&apos;s two findings are CVE-2026-78082 (the SQL injection, published by the Joomla CNA at 9.3 Critical and credited to Phil Taylor of mySites.guru) and CVE-2026-78303 (the mail relay). The release also fixed CVE-2026-78083, CVE-2026-78084 and CVE-2026-78302, which mySites.guru did not report. All five CVE records were published at MITRE on 10 September 2026. Update to SP Property Finder 4.1.4 or later from JoomShaper. Updating closes the flaw but does not undo any database read that already happened: if a vulnerable version was public for a while, treat the password hashes and the site secret as potentially known.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>SP Property Finder</category><category>Critical</category><category>CVE-2026-78082</category><category>CVE-2026-78303</category><category>CVE-2026-78083</category><category>CVE-2026-78084</category><category>CVE-2026-78302</category><category>CVE-2026-78085</category></item><item><title>JooDatabase (com_joodb) below 5.1 - Unauthenticated SQL Injection</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78080/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-423</guid><description>JooDatabase versions before 5.1 pass the front-end cid request parameter straight into a SQL WHERE clause without escaping it. The catalog view reads cid from the request and interpolates each value raw, so an anonymous visitor needs no account, no token and no user interaction to inject arbitrary SQL and read anything the site database holds, including the Joomla user table and its password hashes. CVSS 9.3 Critical (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H), CWE-89. Found by Krzysztof Zajac of CERT PL. Joomla 4, 5 and 6: update to JooDatabase 5.1, released 3 September 2026. The vendor update stream does serve this release to Joomla 4, 5 and 6, so it appears in the normal Update your extensions screen. It can also be installed by hand from https://joodb.feenders.de/index.php/download. Joomla 3 has no fix, and the Joomla backend will not tell those site owners that. The vendor Joomla 3 branch is still com_joodb-3x.zip version 3.2 from May 2022, and its models/catalog.php contains the same unescaped cid interpolation, so it is vulnerable too. The vendor update stream offers Joomla 3 sites only a 3.2.0 block, which is lower than most builds people actually run, so a Joomla 3 site sitting on 3.2.1, 3.6.1, 3.9.x or 3.13 is offered nothing at all and reads as up to date forever, while a site on 3.2 or older is offered an update that still contains the bug. Either way the backend is not a reliable signal here. Those sites are stranded rather than behind: the real remediation is migrating to Joomla 4 or later and installing JooDatabase 5.1. Until then, unpublish or uninstall the component, or block the front-end catalog view at the web server or WAF. Note on the CVE wording: the record names the product JooDatabase Lite, but the vendor stopped shipping separate Lite and Pro editions at the start of 2022 and everything since is a single free release, so this applies to any JooDatabase install in range. The CVE structured version list also states 1.0-5.0.0 while its own title and description say below 5.1.0. The vendor release and the shipped code resolve that in favour of below 5.1: the 5.1 zip served by the update stream carries the db-&gt;quote fix, and the 5.0.2 build that preceded it still has the raw interpolation, so 5.0.1 and 5.0.2 are vulnerable.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>JooDatabase</category><category>Critical</category><category>CVE-2026-78080</category></item><item><title>miniOrange SCIM User Provisioning (com_miniorange_scim) free edition 1.0.0 to 4.0.5 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78074/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-427</guid><description>CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, &quot;SCIM User Provisioning for Joomla (free)&quot;, at the CVE&apos;s stated affected range 1.0.0-4.0.5. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange SCIM User Provisioning to 4.0.6 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor&apos;s own claim: the Joomla Extensions Directory listing for this extension shows 4.0.6 with that release date. miniOrange ship more than one SCIM extension for Joomla and the standalone scim-user-provisioning plugin is versioned on a separate line, so this rule is deliberately confined to the com_miniorange_scim component. This rule&apos;s upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component&apos;s endpoints at the web application firewall or web server.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>miniOrange SCIM User Provisioning</category><category>High</category><category>CVE-2026-78074</category></item><item><title>miniOrange Restrict Files / Folders / Media Access (com_miniorange_mediarestriction) free edition 1.0.0 to 3.7 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78074/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-426</guid><description>CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, &quot;Restrict Files / Folders / Media Access for Joomla (free)&quot;, at the CVE&apos;s stated affected range 1.0.0-3.7. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange Restrict Files / Folders / Media Access to 3.8 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor&apos;s own claim: the Joomla Extensions Directory listing for this extension shows 3.8 with that release date. miniOrange also market this extension as the Joomla Content Access Manager, which is the display name connected sites report for it. This rule&apos;s upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component&apos;s endpoints at the web application firewall or web server.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>miniOrange Restrict Files / Folders</category><category>High</category><category>CVE-2026-78074</category></item><item><title>miniOrange OAuth Server (com_miniorange_oauth) free edition 1.0.0 to 5.1.5 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78074/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-425</guid><description>CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, &quot;OAuth Server for Joomla (free)&quot;, at the CVE&apos;s stated affected range 1.0.0-5.1.5. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange OAuth Server to 5.1.6 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor&apos;s own claim: the Joomla Extensions Directory listing for this extension shows 5.1.6 with that release date. This product ships under the same com_miniorange_oauth element as the OAuth Client, so it is matched on the display name rather than the element alone. This rule&apos;s upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component&apos;s endpoints at the web application firewall or web server.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>miniOrange OAuth Client</category><category>High</category><category>CVE-2026-78074</category></item><item><title>miniOrange Login with Azure AD / OAuth OIDC SSO (com_miniorange_oauth) free edition 1.0.0 to 1.2.2 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78074/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-424</guid><description>CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, &quot;OAuth Single Sign-On - OIDC SSO | Login with Azure AD (free)&quot;, at the CVE&apos;s stated affected range 1.0.0-1.2.2. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update OAuth Single Sign-On - OIDC SSO / Login with Azure AD to 1.2.3 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor&apos;s own claim: the Joomla Extensions Directory listing for this extension shows 1.2.3 with that release date. This product ships under the same com_miniorange_oauth element as the OAuth Client but on its own 1.x numbering, so it is matched on the display name rather than the element alone. This rule&apos;s upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component&apos;s endpoints at the web application firewall or web server.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>miniOrange OAuth Client</category><category>High</category><category>CVE-2026-78074</category></item><item><title>J2Store / J2Commerce (com_j2store) 4.1.6 (Joomla 4.1 branch) - Unauthenticated Payment Callback Forgery and Cart Tampering, Backend Privilege Escalation, Guest Address IDOR and Reflected XSS (5 CVEs)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-77999/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-422</guid><description>J2Store / J2Commerce 4.1.6 is affected by five vulnerabilities in com_j2store, disclosed by Phil Taylor (mySites.guru) and fixed by J2Commerce on 31 August 2026. CVE-2026-78069 (CVSS 9.5, Critical): the administrator Apps controller instantiates app-plugin controllers through an appTask delegation path with no com_j2store ACL check anywhere in the code, and the backend node of fof.xml declares no view ACL at all, so FOF defaults an unmatched task to allow rather than deny. Any authenticated Joomla backend user, holding no J2Store permission whatsoever, can trigger #__j2store_* table truncation and traversal-based SQL file execution; only the Joomla core administrator login wall keeps anonymous visitors out, and that checks nothing about com_j2store permissions. CVE-2026-78064 (CVSS 8.8, High): the carts view inherits the generic FOF save task under a wildcard true ACL in fof.xml, and FOF enforces CSRF tokens only on backend HTML requests, not on frontend format=raw requests, so an unauthenticated POST can insert cart rows with an attacker-chosen user_id or session_id, or overwrite an existing row by id. CVE-2026-77999 (CVSS 8.7, High): the PayPal IPN listener treated UNVERIFIED and any non-INVALID response as valid, made its verification request with CURLOPT_SSL_VERIFYPEER disabled, and stored the verdict in a field nothing downstream read, so processing continued regardless of the outcome; separately, omitting mc_gross from the POST body skipped the paid-amount comparison entirely. Unauthenticated requests could confirm orders that were never paid for, or fail legitimate ones. CVE-2026-78065 (CVSS 7.1, High): editAddress() redirected non-owners away only when the loaded address row had a non-empty user_id, and guest checkout rows have none, so any logged-in account guessing a small sequential address_id was shown a guest customer full name, street address and phone number prefilled into the edit form. CVE-2026-78000 (CVSS 5.3, Medium): filter_tag, pricefrom and priceto are echoed unescaped into a hidden input value attribute by J2Html::input(), across all six shipped product-tags templates, giving reflected XSS from a crafted link with no click beyond the initial navigation. FIX: update to 4.1.7 on this 4.1.x branch (the equivalent fixes are 3.3.22 on the Joomla 3 branch and 4.0.22 on 4.0.x). If you cannot update immediately: disable PayPal, or watch pending orders for CONFIRMED or FAILED transitions with no matching PayPal transaction; disable guest checkout; and review every Joomla backend account regardless of privilege level, because the Apps controller issue needs a backend login but no J2Store permission. All five CVE records were published by the Joomla CNA on 3 September 2026 and all five credit Phil Taylor, mySites.guru. The affected ranges are unchanged. Four scores match the vendor advisory; CVE-2026-78069 was raised from the vendor&apos;s 9.4 to 9.5 Critical, and the published vector reads AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, scoring the backend login as an attack requirement (AT:P) rather than a privilege (PR:L).</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>J2Store / J2Commerce</category><category>Critical</category><category>CVE-2026-77999</category><category>CVE-2026-78000</category><category>CVE-2026-78064</category><category>CVE-2026-78065</category><category>CVE-2026-78069</category></item><item><title>J2Store / J2Commerce (com_j2store) 4.0.21 (Joomla 4.0 branch) - Unauthenticated Payment Callback Forgery and Cart Tampering, Backend Privilege Escalation, Guest Address IDOR and Reflected XSS (5 CVEs)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-77999/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-421</guid><description>J2Store / J2Commerce 4.0.21 is affected by five vulnerabilities in com_j2store, disclosed by Phil Taylor (mySites.guru) and fixed by J2Commerce on 31 August 2026. CVE-2026-78069 (CVSS 9.5, Critical): the administrator Apps controller instantiates app-plugin controllers through an appTask delegation path with no com_j2store ACL check anywhere in the code, and the backend node of fof.xml declares no view ACL at all, so FOF defaults an unmatched task to allow rather than deny. Any authenticated Joomla backend user, holding no J2Store permission whatsoever, can trigger #__j2store_* table truncation and traversal-based SQL file execution; only the Joomla core administrator login wall keeps anonymous visitors out, and that checks nothing about com_j2store permissions. CVE-2026-78064 (CVSS 8.8, High): the carts view inherits the generic FOF save task under a wildcard true ACL in fof.xml, and FOF enforces CSRF tokens only on backend HTML requests, not on frontend format=raw requests, so an unauthenticated POST can insert cart rows with an attacker-chosen user_id or session_id, or overwrite an existing row by id. CVE-2026-77999 (CVSS 8.7, High): the PayPal IPN listener treated UNVERIFIED and any non-INVALID response as valid, made its verification request with CURLOPT_SSL_VERIFYPEER disabled, and stored the verdict in a field nothing downstream read, so processing continued regardless of the outcome; separately, omitting mc_gross from the POST body skipped the paid-amount comparison entirely. Unauthenticated requests could confirm orders that were never paid for, or fail legitimate ones. CVE-2026-78065 (CVSS 7.1, High): editAddress() redirected non-owners away only when the loaded address row had a non-empty user_id, and guest checkout rows have none, so any logged-in account guessing a small sequential address_id was shown a guest customer full name, street address and phone number prefilled into the edit form. CVE-2026-78000 (CVSS 5.3, Medium): filter_tag, pricefrom and priceto are echoed unescaped into a hidden input value attribute by J2Html::input(), across all six shipped product-tags templates, giving reflected XSS from a crafted link with no click beyond the initial navigation. FIX: update to 4.0.22 on this 4.0.x branch (the equivalent fixes are 3.3.22 on the Joomla 3 branch and 4.1.7 on 4.1.x). If you cannot update immediately: disable PayPal, or watch pending orders for CONFIRMED or FAILED transitions with no matching PayPal transaction; disable guest checkout; and review every Joomla backend account regardless of privilege level, because the Apps controller issue needs a backend login but no J2Store permission. All five CVE records were published by the Joomla CNA on 3 September 2026 and all five credit Phil Taylor, mySites.guru. The affected ranges are unchanged. Four scores match the vendor advisory; CVE-2026-78069 was raised from the vendor&apos;s 9.4 to 9.5 Critical, and the published vector reads AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, scoring the backend login as an attack requirement (AT:P) rather than a privilege (PR:L).</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>J2Store / J2Commerce</category><category>Critical</category><category>CVE-2026-77999</category><category>CVE-2026-78000</category><category>CVE-2026-78064</category><category>CVE-2026-78065</category><category>CVE-2026-78069</category></item><item><title>J2Store / J2Commerce (com_j2store) 3.3.21 (Joomla 3 branch) - Unauthenticated Payment Callback Forgery and Cart Tampering, Backend Privilege Escalation, Guest Address IDOR and Reflected XSS (5 CVEs)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-77999/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-420</guid><description>J2Store 3.3.21 on the Joomla 3 branch is affected by five vulnerabilities in com_j2store, disclosed by Phil Taylor (mySites.guru) and fixed by J2Commerce on 31 August 2026. CVE-2026-78069 (CVSS 9.5, Critical): the administrator Apps controller instantiates app-plugin controllers through an appTask delegation path with no com_j2store ACL check anywhere in the code, and the backend node of fof.xml declares no view ACL at all, so FOF defaults an unmatched task to allow rather than deny. Any authenticated Joomla backend user, holding no J2Store permission whatsoever, can trigger #__j2store_* table truncation and traversal-based SQL file execution; only the Joomla core administrator login wall keeps anonymous visitors out, and that checks nothing about com_j2store permissions. CVE-2026-78064 (CVSS 8.8, High): the carts view inherits the generic FOF save task under a wildcard true ACL in fof.xml, and FOF enforces CSRF tokens only on backend HTML requests, not on frontend format=raw requests, so an unauthenticated POST can insert cart rows with an attacker-chosen user_id or session_id, or overwrite an existing row by id. CVE-2026-77999 (CVSS 8.7, High): the PayPal IPN listener treated UNVERIFIED and any non-INVALID response as valid, made its verification request with CURLOPT_SSL_VERIFYPEER disabled, and stored the verdict in a field nothing downstream read, so processing continued regardless of the outcome; separately, omitting mc_gross from the POST body skipped the paid-amount comparison entirely. Unauthenticated requests could confirm orders that were never paid for, or fail legitimate ones. CVE-2026-78065 (CVSS 7.1, High): editAddress() redirected non-owners away only when the loaded address row had a non-empty user_id, and guest checkout rows have none, so any logged-in account guessing a small sequential address_id was shown a guest customer full name, street address and phone number prefilled into the edit form. CVE-2026-78000 (CVSS 5.3, Medium): filter_tag, pricefrom and priceto are echoed unescaped into a hidden input value attribute by J2Html::input(), across all six shipped product-tags templates, giving reflected XSS from a crafted link with no click beyond the initial navigation. FIX: update to 3.3.22 on this Joomla 3 branch (the equivalent fixes are 4.0.22 on 4.0.x and 4.1.7 on 4.1.x). If you cannot update immediately: disable PayPal, or watch pending orders for CONFIRMED or FAILED transitions with no matching PayPal transaction; disable guest checkout; and review every Joomla backend account regardless of privilege level, because the Apps controller issue needs a backend login but no J2Store permission. All five CVE records were published by the Joomla CNA on 3 September 2026 and all five credit Phil Taylor, mySites.guru. The affected ranges are unchanged. Four scores match the vendor advisory; CVE-2026-78069 was raised from the vendor&apos;s 9.4 to 9.5 Critical, and the published vector reads AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, scoring the backend login as an attack requirement (AT:P) rather than a privilege (PR:L).</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>J2Store / J2Commerce</category><category>Critical</category><category>CVE-2026-77999</category><category>CVE-2026-78000</category><category>CVE-2026-78064</category><category>CVE-2026-78065</category><category>CVE-2026-78069</category></item><item><title>miniOrange Two Factor Authentication (com_miniorange_twofa) free edition 1.0.0 to 5.0.9 - Unauthenticated Arbitrary Extension Uninstallation (Denial of Service)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78074/</link><guid isPermaLink="false">mysites-guru-joomla-vulnerability-rule-419</guid><description>CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, &quot;Two Factor Authentication 2FA for Joomla (free)&quot;, at the CVE&apos;s stated affected range 1.0.0-5.0.9. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange Two Factor Authentication to 5.0.10 or later. miniOrange released the fix on 1 September 2026. This was verified independently of the vendor&apos;s own claim: the Joomla Extensions Directory listing for this extension shows 5.0.10 with that release date. The CVE record originally contradicted itself on this one, giving 5.1.0 in its HTML solution block against 5.0.10 in the plain-text one. We reported it to the Joomla CNA on 4 September 2026 and the record was corrected to 5.0.10 the same morning, which is what miniOrange gave in writing and what the directory shows. This release came a day later than the rest of the set. This rule&apos;s upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component&apos;s endpoints at the web application firewall or web server.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>miniOrange Two Factor Authentication</category><category>High</category><category>CVE-2026-78074</category></item></channel></rss>