CVE-2026-65754: Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension
Published Jul 23, 2026
·Updated
Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.
Affected Software
1 affected component
Regular Labs ReReplacer Pro
Event History
Jul 23, 2026
CVE Published
via MITRE·09:13 AM
Data Sourced
via MITRE·09:13 AM
DescriptionWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-65754?
CVE-2026-65754 has a risk rating of 47, indicating a significant security concern.
2
How do I fix CVE-2026-65754?
To fix CVE-2026-65754, update the Regular Labs ReReplacer Pro extension to the latest version provided by the vendor.
3
What is the impact of CVE-2026-65754?
CVE-2026-65754 allows attackers to exploit insecure path handling to read files outside the site directory, potentially compromising sensitive data.
4
Which software is affected by CVE-2026-65754?
The vulnerability CVE-2026-65754 affects the Regular Labs ReReplacer Pro extension.
5
When was CVE-2026-65754 published?
CVE-2026-65754 was published on July 23, 2026.