CVE-2026-85189: Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0
Joomla Extension - regularlabs.com - Privileged stored XSS via executable URL schemes in Modals extension for Joomla < 17.0.0 - Modals treats a destination using an executable browser URL scheme as an ordinary modal URL. The value can reach both the generated link and the iframe-loading path. Authored content can consequently become JavaScript in a visitor's browser without using Modals' separate Pro JavaScript Events feature.
Affected Software
Event History
Frequently Asked Questions
Does disabling Modals Pro JavaScript Events prevent this issue?
No. The issue does not rely on Modals' separate Pro JavaScript Events feature; an executable browser URL scheme in authored content can still reach the generated link and iframe-loading path.
Who is exposed to the stored script execution?
Visitors who load authored content containing a malicious Modals destination may have JavaScript run in their browser. Exploitation requires a party able to author or alter such content.