CVE-2026-74253: Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0
Published Aug 17, 2026
·Updated
Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 14.0.0 - Regular Labs Sourcerer before 14.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining where that code originated.
Affected Software
1 affected component
Regular Labs Sourcerer<14.0.0
Event History
Aug 17, 2026
CVE Published
via MITRE·05:12 PM
Data Sourced
via MITRE·05:12 PM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-74253?
CVE-2026-74253 has a risk score of 89, indicating a high severity vulnerability.
2
How do I fix CVE-2026-74253?
To fix CVE-2026-74253, update Regular Labs Sourcerer to version 14.0.0 or later.
3
What type of vulnerability is CVE-2026-74253?
CVE-2026-74253 is a code injection vulnerability that allows unauthenticated remote code execution.
4
Which software is affected by CVE-2026-74253?
CVE-2026-74253 affects the Regular Labs Sourcerer extension for Joomla.
5
What is the cause of CVE-2026-74253?
CVE-2026-74253 is caused by unverified reflected user input in the processing of {source} blocks.