SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-63684

HIGH · CVSS 8.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

Multiple Regular Labs extensions for Joomla exhibit inconsistent CSRF token and privilege checks in various admin actions, allowing unauthorized backend users to exploit these vulnerabilities. This could lead to unauthorized exposure, creation, or modification of extension configurations and items. Joomla administrators and users of Regular Labs extensions should prioritize addressing this vulnerability to mitigate the risk of CSRF attacks.

CVE
CVE-2026-63684
Severity
HIGH
CVSS
8.8
EPSS
0.13%

Original NVD Description

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and items.