๐Ÿ” CVE Alert

CVE-2026-85191

UNKNOWN 0.0

Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

Joomla Extension - regularlabs.com - Privileged stored XSS via rtla-alias option in Tabs & Accordions extension for Joomla < 3.1.0 - Tabs & Accordions rewrites links matching an item alias into calls to its browser API. The affected renderer places the alias inside a quoted JavaScript argument in an HTML onclick attribute without securing both the JavaScript-string and HTML-attribute contexts. A crafted data-rlta-alias value can therefore change the generated handler.

CWE CWE-79
Vendor regularlabs.com
Product tabs & accordions (free, pro) extension for joomla
Published Sep 14, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for regularlabs.com tabs & accordions (free, pro) extension for joomla

Be the first to know when new unknown vulnerabilities affecting regularlabs.com tabs & accordions (free, pro) extension for joomla are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

regularlabs.com / Tabs & Accordions (Free, Pro) extension for Joomla
1.0.0-3.0.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
regularlabs.com: https://www.regularlabs.com/