Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://regularlabs.com/ |
|
Tue, 28 Jul 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Regularlabs.com
Regularlabs.com advanced Module Manager Extension For Joomla Regularlabs.com conditional Content Extension For Joomla Regularlabs.com content Templater Pro Extension For Joomla Regularlabs.com rereplacer Extension Pro For Joomla |
|
| Vendors & Products |
Regularlabs.com
Regularlabs.com advanced Module Manager Extension For Joomla Regularlabs.com conditional Content Extension For Joomla Regularlabs.com content Templater Pro Extension For Joomla Regularlabs.com rereplacer Extension Pro For Joomla |
Thu, 23 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules. | Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules. |
Wed, 22 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules. | |
| Title | Joomla Extension - regularlabs.com - Client IP spoofing vulnerability in Regular Labs conditions manager | |
| Weaknesses | CWE-290 | |
| References |
|
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-07-28T05:33:18.651Z
Reserved: 2026-07-17T15:49:15.531Z
Link: CVE-2026-63683
Updated: 2026-07-27T18:44:26.428Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-28T17:30:12Z
-
CWE-290
Authentication Bypass by Spoofing