CVE-2026-85188 PUBLISHED

Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla

Assigner: Joomla
Reserved: 03.09.2026 Published: 14.09.2026 Updated: 14.09.2026

Joomla Extension - regularlabs.com - Database data disclosure in Advanced Module Manager (Free, Pro) < 12.1.0, Conditional Content (Free, Pro) < 8.0.0, Content Templater (Pro) < 14.2.0, ReReplacer (Pro) < 16.2.0 for Joomla - The Conditions editor creates a default Condition Set name from the item to which the set is linked. The affected code accepts the database table and label-column names from the request. Although these names are quoted as SQL identifiers, they are not restricted to the tables and columns used by supported Regular Labs integrations. An attacker can therefore select a valid but unrelated database field. This is an authorization failure rather than SQL injection.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor regularlabs.com
Product Advanced Module Manager (Free, Pro) extension for Joomla
Versions Default: unaffected
  • Version 9.0.0-12.0.4 is affected
Vendor regularlabs.com
Product Conditional Content (Free, Pro) extension for Joomla
Versions Default: unaffected
  • Version 4.0.0-7.1.0 is affected
Vendor regularlabs.com
Product Content Templater (Pro) extension for Joomla
Versions Default: unaffected
  • Version 11.0.0-14.1.0 is affected
Vendor regularlabs.com
Product ReReplacer (Pro) extension for Joomla
Versions Default: unaffected
  • Version 12.2.0-16.1.0 is affected

References

Problem Types

  • CWE-200 Exposure of Sensitive Information to an Unauthorized Actor CWE