CVE-2026-85191
Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions rewrites links matching an item alias into calls to its browser API. The affected renderer places the alias inside a quoted JavaScript argument in an HTML onclick attribute without securing both the JavaScript-string and HTML-attribute contexts. A crafted data-rlta-alias value can therefore change the generated handler.
| CWE | CWE-79 |
| Vendor | regularlabs.com |
| Product | tabs & accordions (free, pro) extension for joomla |
| Published | Sep 14, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for regularlabs.com tabs & accordions (free, pro) extension for joomla
Be the first to know when new unknown vulnerabilities affecting regularlabs.com tabs & accordions (free, pro) extension for joomla are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
regularlabs.com / Tabs & Accordions (Free, Pro) extension for Joomla
1.0.0-3.0.5