CVE-2026-85196 PUBLISHED

Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0

Assigner: Joomla
Reserved: 03.09.2026 Published: 14.09.2026 Updated: 14.09.2026

Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context in which the tag is used. Joomla's string input filter does not make the same value safe for HTML text, an HTML attribute and a URL. A visitor-controlled request value can therefore become an executable URL or a new event attribute in output configured by a site author.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor regularlabs.com
Product Articles Anywhere (Pro) extension for Joomla
Versions Default: unaffected
  • Version 8.4.0-19.0.6 is affected
Vendor regularlabs.com
Product Users Anywhere (Pro) extension for Joomla
Versions Default: unaffected
  • Version 1.0.0-2.0.6 is affected

References

Problem Types

  • CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') CWE