SecAlerts
r

regular labs

Security Risk Profile

60
/100
high

Security Risk Score

Comprehensive risk assessment based on 11 vulnerabilities, EPSS scores, exploitation status, and remediation availability.

📅 Data spans from February 4, 2025 to present

11
Total CVEs
9
Critical+High
0
Exploited
9
Unpatched

Threat Assessment

Avg CVSS
8
Base severity
Avg EPSS
0%
Exploit probability
Unpatched
9
Critical/High
Risk Level
60/100
high
📈 4 in Last 30 Days

Severity Distribution

Critical
3
High
6
Medium
2
Low
0

Exploit Likelihood

>50% chance
0
20-50%
0
5-20%
0
<5%
0

Age Distribution

Common Weaknesses (CWE)

1
XSS
3
2
Path Traversal
2
3
CSRF
2
4
Code Injection
2
5
SSRF
1

Most Affected Products

1. Regular Labs Modules Anywhere2
2. Regular Labs Tabs & Accordions Pro1
3. Regular Labs Articles Anywhere (extension for Joomla)1
4. Regular Labs Users Anywhere (extension for Joomla)1
5. Regular Labs Tabs & Accordions extension for Joomla1

Recent Vulnerabilities

See more →
CVE-2026-100750
CVSS 8.5high

Joomla Extension - regularlabs.com - Arbitrary file read / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla

Sep 28, 2026🔧 No Patch
CVE-2026-100751
CVSS 7.5high

Joomla Extension - regularlabs.com - Privileged stored XSS via data-rlta-url attributes in Tabs & Accordions (Pro) 2.3.0 - 3.1.0

Sep 28, 2026🔧 No Patch
CVE-2026-85196
CVSS 5.3medium

Joomla Extension - regularlabs.com - Reflected XSS in Articles Anywhere extension for Joomla < 20.0.0, Users Anywhere extension for Joomla < 2.1.0

Sep 14, 2026🔧 No Patch
CVE-2026-85191
CVSS 7.5high

Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0

Sep 14, 2026🔧 No Patch
CVE-2026-65713
CVSS 6.5medium

Joomla Extension - regularlabs.com - Insecure path handling in Modals Pro extension

Jul 23, 2026🔧 No Patch
CVE-2026-65754
CVSS 7.5high

Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension

Jul 23, 2026🔧 No Patch
CVE-2026-64793
CVSS 9.1critical

Joomla Extension - regularlabs.com - Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions

Jul 22, 2026🔧 No Patch
CVE-2026-63265
CVSS 8.0high

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints

Jul 22, 2026🔧 No Patch
CVE-2026-64796
CVSS 9.8critical

Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension

Jul 22, 2026🔧 No Patch
CVE-2026-63684
CVSS 8.8high

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension

Jul 22, 2026🔧 No Patch

Monitor regular labs in Real-Time

Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.

Powered bySecAlerts

Monitor Your Software Stack in Real-Time

Get instant alerts when vulnerabilities are discovered in your software stack. Stay ahead of security threats with SecAlerts.

© 2026 SecAlerts Pty Ltd. All rights reserved.

regular labs Security Vulnerabilities & Risk Score | 11 CVEs | SecAlerts - SecAlerts