CVE-2026-63265: Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, matching component/item permissions and trusted server-generated form configuration. Authenticated lower-privileged users or CSRF attacks could invoke lookups or mutations outside their authorization.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63265?
CVE-2026-63265 has a risk score of 44, indicating a moderate severity level.
How do I fix CVE-2026-63265?
To fix CVE-2026-63265, ensure all AJAX endpoints require valid CSRF tokens and enforce proper privilege checks for users.
What type of vulnerabilities does CVE-2026-63265 address?
CVE-2026-63265 addresses inconsistent CSRF token and privilege checks in AJAX endpoints.
Which software is affected by CVE-2026-63265?
CVE-2026-63265 affects various AJAX endpoints in Regular Labs Joomla extensions.
When was CVE-2026-63265 published?
CVE-2026-63265 was published on July 22, 2026.