Vulnerability Description
Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover. In affected versions, those options become real HTML event attributes without checking the article author's trust level. The plugin syntax survives Joomla's normal Author content filter because the executable HTML is generated later.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-85195?
CVE-2026-85195 is a documented vulnerability. Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover. ...
How severe is CVE-2026-85195?
CVSS scoring is not yet available for CVE-2026-85195. Check NVD for updates.
Is there a patch for CVE-2026-85195?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.