CVE-2026-85189
moderatePrivileged Stored XSS via Executable URL Schemes in Regular Labs Modals for Joomla
Regular Labs' Modals extension for Joomla, in all versions before 17.0.0, treats a modal destination that uses an executable browser URL scheme (such as javascript:) as an ordinary modal URL. A user with high authoring privileges can store such a destination in content, and the value flows unchecked into both the generated link and the iframe-loading path. When a visitor views the content or opens the modal, the stored value can execute as JavaScript in that visitor's browser — bypassing Modals' separate, gated Pro JavaScript Events feature — enabling session/cookie theft or actions in the victim's context, up to administrator account takeover. Any Joomla site running Modals below 17.0.0 is affected, with practical risk concentrated on sites where semi-trusted users hold authoring or editing permissions. No public proof of concept exists, the flaw is not on the CISA KEV list, and no exploitation in the wild is known.
What to do: Update Modals to version 17.0.0 or later on all Joomla sites as soon as possible. Audit existing articles and modal destinations for executable URL schemes (e.g., javascript:, data:, vbscript:) and remove or sanitize any found. Restrict authoring and editing privileges to trusted users, since exploitation requires high privileges to plant the stored payload.
| Regular Labs (regularlabs.com) Modals (Joomla extension) | < 17.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL. The value can reach both the generated link and the iframe-loading path. Authored content can consequently become JavaScript in a visitor's browser without using Modals' separate Pro JavaScript Events feature.
- Ecosystems
- Joomla
- Weakness
- CWE-79
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.