Vulnerability Description
Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed. Affected versions do not distinguish trusted extension configuration from event code supplied in ordinary article content. A lower-privileged author can therefore use a documented executable feature which should be reserved for trusted authors.
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-88853?
CVE-2026-88853 is a documented vulnerability. Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open an...
How severe is CVE-2026-88853?
CVSS scoring is not yet available for CVE-2026-88853. Check NVD for updates.
Is there a patch for CVE-2026-88853?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.