CVE-2026-85189: Regularlabs.com Modals Free, Pro Extension For Joomla

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL. The value can reach both the generated link and the iframe-loading path. Authored content can consequently become JavaScript in a visitor's browser without using Modals' separate Pro JavaScript Events feature.

Affected products

  • Regularlabs.com Modals Free, Pro Extension For Joomla: version 4.0.0-16.2.0 only

Published 2026-09-14. Last modified 2026-09-16.