SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64799

HIGH · CVSS 7.5 EPSS 0.31%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The Joomla extensions Articles Anywhere and Users Anywhere are vulnerable due to their handling of content-controlled image URLs, which can be exploited to perform Server-Side Request Forgery (SSRF) attacks. This vulnerability allows attackers to access private network services, potentially exfiltrate internal data, or write malicious files to a web-accessible directory. Organizations using these extensions should prioritize remediation to mitigate the risk of unauthorized access and data breaches.

CVE
CVE-2026-64799
Severity
HIGH
CVSS
7.5
EPSS
0.31%

Original NVD Description

Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder.