Vulnerability Description
Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return values from request-input data tags without making them safe for the context in which the tag is used. Joomla's string input filter does not make the same value safe for HTML text, an HTML attribute and a URL. A visitor-controlled request value can therefore become an executable URL or a new event attribute in output configured by a site author.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-85196?
CVE-2026-85196 is a documented vulnerability. Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0 - Articles Anywhere Pro and Users Anywhere Pro return...
How severe is CVE-2026-85196?
CVSS scoring is not yet available for CVE-2026-85196. Check NVD for updates.
Is there a patch for CVE-2026-85196?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.