CVE-2026-65754 PUBLISHED

Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension

Assigner: Joomla
Reserved: 22.07.2026 Published: 23.07.2026 Updated: 23.07.2026

Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.

Product Status

Vendor regularlabs.com
Product ReReplacer PRo extension for Joomla
Versions Default: unaffected
  • Version 1.0.0-15.0.3 is affected

References

Problem Types

  • CWE-22 Improper Limitation of a Pathname to a Restricted Directory CWE

Impacts

  • CAPEC-126 Path Traversal