CVE-2026-85189: Regularlabs.com Modals Free, Pro Extension For Joomla
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL. The value can reach both the generated link and the iframe-loading path. Authored content can consequently become JavaScript in a visitor's browser without using Modals' separate Pro JavaScript Events feature.
Affected products
- Regularlabs.com Modals Free, Pro Extension For Joomla: version 4.0.0-16.2.0 only
Published 2026-09-14. Last modified 2026-09-16.