CVE-2026-85191
largePrivileged Stored XSS in Regular Labs Tabs & Accordions for Joomla (before 3.1.0)
Tabs & Accordions, a Joomla extension from Regular Labs (regularlabs.com), contains a stored cross-site scripting (XSS) flaw in all versions before 3.1.0: the extension rewrites links matching an item alias into calls to its browser API and places that alias inside a quoted JavaScript argument within an HTML onclick attribute, without escaping either the JavaScript-string or the HTML-attribute context. An attacker with the privileged access needed to set the rtla-alias option (for example, a backend user permitted to edit the extension's items or relevant content) can supply a crafted data-rlta-alias value that alters the generated click handler and executes attacker-controlled JavaScript. Because the payload is stored and fires with no victim interaction, it can target higher-privileged users such as site administrators, enabling session theft and full site takeover (CVSS 4.0: 7.5, high). Affected deployments are Joomla sites running Tabs & Accordions earlier than 3.1.0, particularly those where semi-trusted users hold content- or extension-editing rights. The flaw is not in CISA's KEV catalog, and no public proof of concept or observed in-the-wild exploitation is known.
What to do: Upgrade Tabs & Accordions to version 3.1.0 or later, which remediates the flaw. Audit existing articles and extension items for suspicious data-rlta-alias values or unexpected onclick handlers, and restrict which backend accounts are allowed to edit those items. If tampering is found, remove the injected content and reset administrator sessions and credentials.
| Regular Labs (regularlabs.com) Tabs & Accordions (Joomla extension) | All versions prior to 3.1.0 (< 3.1.0) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions rewrites links matching an item alias into calls to its browser API. The affected renderer places the alias inside a quoted JavaScript argument in an HTML onclick attribute without securing both the JavaScript-string and HTML-attribute contexts. A crafted data-rlta-alias value can therefore change the generated handler.
- Ecosystems
- Joomla
- Weakness
- CWE-79
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.