Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://regularlabs.com/ |
|
Tue, 28 Jul 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Thu, 23 Jul 2026 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Regularlabs.com
Regularlabs.com sourcerer Extension For Joomla |
|
| Vendors & Products |
Regularlabs.com
Regularlabs.com sourcerer Extension For Joomla |
Thu, 23 Jul 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection. | Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection. |
Wed, 22 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection. | |
| Title | Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension | |
| Weaknesses | CWE-284 | |
| References |
|
Status: PUBLISHED
Assigner: Joomla
Published:
Updated: 2026-07-28T05:34:08.793Z
Reserved: 2026-07-20T18:16:31.593Z
Link: CVE-2026-64796
Updated: 2026-07-27T18:43:46.172Z
No data.
No data.
OpenCVE Enrichment
Updated: 2026-07-30T08:45:14Z
-
CWE-284
Improper Access Control