SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-85189

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Modals extension for Joomla versions prior to 17.0.0 is vulnerable to a privileged stored cross-site scripting (XSS) attack due to improper handling of executable URL schemes. This flaw allows attackers to inject malicious JavaScript into user browsers, potentially compromising user data and session integrity. Joomla site administrators and developers using the Modals extension should prioritize patching this vulnerability to protect their users from exploitation.

CVE
CVE-2026-85189
Severity
HIGH
CVSS
7.5
EPSS
0.25%
Java

Original NVD Description

Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL. The value can reach both the generated link and the iframe-loading path. Authored content can consequently become JavaScript in a visitor's browser without using Modals' separate Pro JavaScript Events feature.