Security Advisory

CVE-2026-88853

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-09-14 06:13:38
Last updated 2026-09-15 04:41:10
Assigner Joomla
CVSS score 7.5
State PUBLISHED

Description

Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed. Affected versions do not distinguish trusted extension configuration from event code supplied in ordinary article content. A lower-privileged author can therefore use a documented executable feature which should be reserved for trusted authors.