ZeroHour

CVE-2026-88852

moderate

Privileged Stored XSS in Regular Labs Snippets Extension for Joomla

CVSS 4.0
7.5 high
EPSS
Published
()
Modified
AI analysis

Regular Labs Snippets for Joomla contains a stored cross-site scripting (XSS) flaw in how the extension substitutes variable values supplied through article tags into saved Snippet content. Because affected versions do not check the article author's trust level, a lower-privileged author can inject an unsafe value — for example via the url option — into a security-sensitive position in content designed by a trusted Snippet author. Successful exploitation causes the attacker's script to execute in the browsers of site visitors or higher-privileged users such as administrators, enabling cookie/session theft or malicious actions taken as the victim. The affected products are Snippets Free for Joomla before 7.0.0 and Snippets Pro for Joomla before 11.0.0, rated high severity (CVSS 4.0: 7.5) with the attack requiring attacker preparation and author-level privileges. The flaw is not in CISA's KEV catalog, and no public proof of concept or observed in-the-wild exploitation is known.

What to do: Upgrade Snippets Free to version 7.0.0 or later, and Snippets Pro to version 11.0.0 or later. Audit articles authored by low-privilege users for Snippet tags containing unexpected url or variable values, and review site logs for injected script payloads. Until patched, consider restricting authoring permissions or Snippet usage to trusted users only.

Affected
Regular Labs (regularlabs.com) Snippets Free for Joomla< 7.0.0
Regular Labs (regularlabs.com) Snippets Pro for Joomla< 11.0.0
Estimated exposure
moderatelikely tens of thousands of Joomla sites (order of magnitude: 10k–100k installations) — Joomla powers roughly 1.5–2% of websites worldwide (~1–2 million sites) and Snippets is a popular but not top-tier Regular Labs extension, suggesting a low-to-mid tens-of-thousands install base; the vendor does not publish active-install…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Joomla Extension - regularlabs.com - Privileged stored XSS via url option in Snippets Free extension for Joomla < 7.0.0, Snippets Pro extension for Joomla < 11.0.0 - Snippets substitutes variable values supplied by an article tag into saved Snippet content. The affected versions do not consider the article author's trust level. A lower-privileged author can therefore place an unsafe value into a security-sensitive position chosen by the trusted Snippet author.

Ecosystems
Joomla
Weakness
CWE-79
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.