Users Anywhere (usersanywhere) below 2.0.0 - SSRF, Stored XSS and Sensitive Data Exposure
Regular Labs Users Anywhere before 2.0.0 is affected by issues fixed in the coordinated Regular Labs security release of 22 July 2026 (no CVE assigned): external image downloads accepting unsafe hosts, redirects, non-image responses or local download folders (SSRF); tag-provided field custom HTML overrides able to render unsafe markup (stored XSS); and tags able to expose authentication data or restricted contact details. Several fixes are BC breaks (field custom HTML now renders as escaped text). Update to Users Anywhere 2.0.0 or later. CVE ids assigned by the Joomla CNA for this extension in the 22 July 2026 Regular Labs security release: CVE-2026-64794, CVE-2026-64795, CVE-2026-64799, CVE-2026-65755.
Affected versions: ≤ 1.2.7
Full advisory: regularlabs.com