CVE-2026-85190: Regularlabs.com Quick Index Free, Pro Extension For Joomla

High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.

Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. A crafted value can close the intended class attribute and introduce a new attribute. Joomla's content filter cannot reliably prevent this because Quick Index creates the executable HTML after the authored plugin syntax was filtered.

Affected products

  • Regularlabs.com Quick Index Free, Pro Extension For Joomla: version 1.0.0-5.0.4 only

Published 2026-09-14. Last modified 2026-09-16.