Vulnerability Description
Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL. The value can reach both the generated link and the iframe-loading path. Authored content can consequently become JavaScript in a visitor's browser without using Modals' separate Pro JavaScript Events feature.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-85189?
CVE-2026-85189 is a documented vulnerability. Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an...
How severe is CVE-2026-85189?
CVSS scoring is not yet available for CVE-2026-85189. Check NVD for updates.
Is there a patch for CVE-2026-85189?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.