CVE-2026-64796: Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension
Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-64796?
CVE-2026-64796 has a risk rating of 72, indicating a significant vulnerability that should be addressed promptly.
How do I fix CVE-2026-64796?
To fix CVE-2026-64796, ensure that the Sourcerer extension is updated to the latest version provided by Regular Labs.
What types of code injection are involved in CVE-2026-64796?
CVE-2026-64796 involves various code injection vectors that can be exploited through the configuration of article PHP execution.
Who is affected by CVE-2026-64796?
Both free and pro users of the Regular Labs Joomla! Extension - Sourcerer are potentially affected by CVE-2026-64796.
What should I do if CVE-2026-64796 is exploited?
If CVE-2026-64796 is exploited, it is crucial to immediately update the extension and perform an audit of your site for unauthorized changes.