CVE-2026-88853
moderatePrivileged Stored XSS via Event Handlers in Regular Labs Modals Pro for Joomla
Regular Labs Modals Pro for Joomla, in all versions before 17.0.0, contains a privileged stored cross-site scripting (XSS) flaw because its documented JavaScript event-handler feature (such as on-open and on-closed) is not restricted to trusted extension configuration. An authenticated attacker holding only author-level privileges can embed executable event code in ordinary article content, and that script then runs in the browser of any user — including a site administrator — who views the page. Successful exploitation gives the attacker script execution in a higher-privileged user's session, which can be leveraged for administrative actions such as content tampering, further account compromise, or site takeover. Sites running Modals Pro below 17.0.0 that allow non-trusted users to author articles are the most exposed; only the third-party extension is affected, not Joomla core. There is no evidence of exploitation in the wild, no public proof of concept, and the CVE is not on CISA's Known Exploited Vulnerabilities catalog.
What to do: Upgrade Modals Pro to version 17.0.0 or later, where the event-handler feature is reserved for trusted extension configuration. Until then, restrict article authoring to fully trusted staff and review existing articles for {modal} tags containing on-open/on-closed or other event attributes from untrusted contributors. Also audit author-level user accounts for suspicious or unauthorized registrations, since the flaw requires an authenticated author account to exploit.
| Regular Labs (regularlabs.com) Modals Pro (Joomla extension) | < 17.0.0 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed. Affected versions do not distinguish trusted extension configuration from event code supplied in ordinary article content. A lower-privileged author can therefore use a documented executable feature which should be reserved for trusted authors.
- Ecosystems
- Joomla
- Weakness
- CWE-79
- Vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.