NONE · 0

CVE-2026-88853

Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open an...

Vulnerability Description

Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed. Affected versions do not distinguish trusted extension configuration from event code supplied in ordinary article content. A lower-privileged author can therefore use a documented executable feature which should be reserved for trusted authors.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-88853?

CVE-2026-88853 is a documented vulnerability. Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open an...

How severe is CVE-2026-88853?

CVSS scoring is not yet available for CVE-2026-88853. Check NVD for updates.

Is there a patch for CVE-2026-88853?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.