CVE-2026-63684: Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension
Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and items.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-63684?
CVE-2026-63684 has a risk rating of 51, indicating a moderate severity vulnerability.
What vulnerabilities are associated with CVE-2026-63684?
CVE-2026-63684 is associated with inconsistent CSRF token checks and privilege checks in multiple Regular Labs extensions.
How do I fix CVE-2026-63684?
To fix CVE-2026-63684, ensure that all admin actions and import/export requests have consistent CSRF token validation and proper privilege checks.
Which software is affected by CVE-2026-63684?
CVE-2026-63684 affects various Regular Labs Joomla extensions available at regularlabs.com.
What actions are impacted by CVE-2026-63684?
CVE-2026-63684 impacts admin actions, editor popups, and import/export requests due to inconsistent checks.