ZeroHour

CVE-2026-85191

large

Privileged Stored XSS in Regular Labs Tabs & Accordions for Joomla (before 3.1.0)

CVSS 4.0
7.5 high
EPSS
Published
()
Modified
AI analysis

Tabs & Accordions, a Joomla extension from Regular Labs (regularlabs.com), contains a stored cross-site scripting (XSS) flaw in all versions before 3.1.0: the extension rewrites links matching an item alias into calls to its browser API and places that alias inside a quoted JavaScript argument within an HTML onclick attribute, without escaping either the JavaScript-string or the HTML-attribute context. An attacker with the privileged access needed to set the rtla-alias option (for example, a backend user permitted to edit the extension's items or relevant content) can supply a crafted data-rlta-alias value that alters the generated click handler and executes attacker-controlled JavaScript. Because the payload is stored and fires with no victim interaction, it can target higher-privileged users such as site administrators, enabling session theft and full site takeover (CVSS 4.0: 7.5, high). Affected deployments are Joomla sites running Tabs & Accordions earlier than 3.1.0, particularly those where semi-trusted users hold content- or extension-editing rights. The flaw is not in CISA's KEV catalog, and no public proof of concept or observed in-the-wild exploitation is known.

What to do: Upgrade Tabs & Accordions to version 3.1.0 or later, which remediates the flaw. Audit existing articles and extension items for suspicious data-rlta-alias values or unexpected onclick handlers, and restrict which backend accounts are allowed to edit those items. If tampering is found, remove the injected content and reset administrator sessions and credentials.

Affected
Regular Labs (regularlabs.com) Tabs & Accordions (Joomla extension)All versions prior to 3.1.0 (< 3.1.0)
Estimated exposure
largeTens of thousands of Joomla sites (order of magnitude ~10,000-100,000 installations); estimate only — Regular Labs is one of the most widely installed Joomla extension vendors and Joomla itself runs on roughly 1-2 million live sites per public web-technology surveys, so assuming a low single-digit percentage adoption of this popular plugin…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions rewrites links matching an item alias into calls to its browser API. The affected renderer places the alias inside a quoted JavaScript argument in an HTML onclick attribute without securing both the JavaScript-string and HTML-attribute contexts. A crafted data-rlta-alias value can therefore change the generated handler.

Ecosystems
Joomla
Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.