CVE-2026-74253: Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0
Published Aug 17, 2026
·Updated
Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 - Regular Labs Sourcerer before 16.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining where that code originated.
Affected Software
1 affected component
Joomla Extension - Regular Labs Sourcerer<16.0.0
Event History
Aug 17, 2026
CVE Published
via MITRE·05:12 PM
Data Sourced
via MITRE·05:12 PM
DescriptionWeakness
Data Sourced
via NVD·06:18 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-74253?
CVE-2026-74253 has a risk score of 89, indicating a high severity vulnerability.
2
How do I fix CVE-2026-74253?
To fix CVE-2026-74253, update Regular Labs Sourcerer to version 14.0.0 or later.
3
What type of vulnerability is CVE-2026-74253?
CVE-2026-74253 is a code injection vulnerability that allows unauthenticated remote code execution.
4
Which software is affected by CVE-2026-74253?
CVE-2026-74253 affects the Regular Labs Sourcerer extension for Joomla.
5
What is the cause of CVE-2026-74253?
CVE-2026-74253 is caused by unverified reflected user input in the processing of {source} blocks.