Search Results (29 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2026-65431 1 Regularlabs.com 1 Geoip Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - Zipslip in GeoIP extension - Geo IP database update archives have been broadly extracted without path validation, leading to unsafe file extractions.
CVE-2026-65430 1 Regularlabs.com 1 Geoip Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - MaxMind Credential leakage in GeoIP extension - MaxMind credentials where leaked in request URLs, causing a credential leakage vulnerability.
CVE-2026-64799 1 Regularlabs.com 2 Articles Anywhere Pro Extension For Joomla, Users Anywhere Pro Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder.
CVE-2026-64874 1 Regularlabs.com 1 Cache Cleaner Pro Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - CDN Credential leakage Cache Cleaner Pro extension - CDN credentials were exposed in administrator request URLs.
CVE-2026-65756 1 Regularlabs.com 1 Keyboard Shortcuts Extension For Joomla 2026-07-23 6.1 Medium
Joomla Extension - regularlabs.com - XSS vector in Keyboard Shortcuts extension - Shortcut configuration accepted arbitrary inline JavaScript.
CVE-2026-64876 1 Regularlabs.com 1 Geoip Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.
CVE-2026-64875 1 Regularlabs.com 1 Geoip Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.
CVE-2026-65754 1 Regularlabs.com 1 Rereplacer Pro Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.
CVE-2026-65755 1 Regularlabs.com 2 Articles Anywhere Extension For Joomla, Users Anywhere Extension For Joomla 2026-07-23 N/A
Joomla Extension - regularlabs.com - Date-sensitive query-cache leakage in Articles Anywhere and Users Anywhere extension - Date-sensitive query cache keys did not retain a bounded time component. Cached results could remain active across future publication or expiry boundaries, potentially exposing content after it should become unavailable.