ZeroHour

CVE-2026-85189

moderate

Privileged Stored XSS via Executable URL Schemes in Regular Labs Modals for Joomla

CVSS 4.0
7.5 high
EPSS
Published
()
Modified
AI analysis

Regular Labs' Modals extension for Joomla, in all versions before 17.0.0, treats a modal destination that uses an executable browser URL scheme (such as javascript:) as an ordinary modal URL. A user with high authoring privileges can store such a destination in content, and the value flows unchecked into both the generated link and the iframe-loading path. When a visitor views the content or opens the modal, the stored value can execute as JavaScript in that visitor's browser — bypassing Modals' separate, gated Pro JavaScript Events feature — enabling session/cookie theft or actions in the victim's context, up to administrator account takeover. Any Joomla site running Modals below 17.0.0 is affected, with practical risk concentrated on sites where semi-trusted users hold authoring or editing permissions. No public proof of concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild is known.

What to do: Update Modals to version 17.0.0 or later on all Joomla sites as soon as possible. Audit existing articles and modal destinations for executable URL schemes (e.g., javascript:, data:, vbscript:) and remove or sanitize any found. Restrict authoring and editing privileges to trusted users, since exploitation requires high privileges to plant the stored payload.

Affected
Regular Labs (regularlabs.com) Modals (Joomla extension)< 17.0.0
Estimated exposure
moderatetens of thousands of Joomla sites (order of 10,000–100,000; clearly an estimate) — Joomla powers roughly 1.5–2% of all websites (a base of a few million sites) and Modals is one of Regular Labs' widely deployed extensions, but no official active-install count was available.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL. The value can reach both the generated link and the iframe-loading path. Authored content can consequently become JavaScript in a visitor's browser without using Modals' separate Pro JavaScript Events feature.

Ecosystems
Joomla
Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.