CVE-2026-100750

HIGHCVSS 8.5/10

Last modified

CVE-2026-100750 is a high-severity vulnerability rated 8.5/10 on the CVSS scale. Joomla Extension - regularlabs.com - LFI / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla - Modules Anywhere Pro lets additional attributes on a module tag replace arbitrary parameters of the selected module. This feature is enabled by default in affected versions.

Description

Joomla Extension - regularlabs.com - LFI / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla - Modules Anywhere Pro lets additional attributes on a module tag replace arbitrary parameters of the selected module. This feature is enabled by default in affected versions. The overrides are applied without checking who authored the content containing the tag. The security effect depends on how the selected module consumes the replaced parameter. Joomla's core Feed module provides a concrete affected path: its rssurl parameter is opened by the server and accepts local file: URLs as well as network URLs.

Metrics

Weakness Enumeration

Affected Software

Source: CNA advisory (CVE.org). NVD analysis pending.

VendorProductVersions
regularlabs.comModules Anywhere (Pro) extension for Joomla1.5.0-9.0.5

References

Timeline

Published
Last Modified
Status
Received

Frequently Asked Questions

What is CVE-2026-100750?
Joomla Extension - regularlabs.com - LFI / SSRF in Modules Anywhere 1.5.0 - 9.0.5 for Joomla - Modules Anywhere Pro lets additional attributes on a module tag replace arbitrary parameters of the selected module. This feature is enabled by default in affected versions. The overrides are applied without checking who authored the content containing the tag. The security effect depends on how the selected module consumes the replaced parameter. Joomla's core Feed module provides a concrete affected path: its rssurl parameter is opened by the server and accepts local file: URLs as well as network URLs.
How severe is CVE-2026-100750?
CVE-2026-100750 has a CVSS score of 8.5/10 (HIGH severity).
How do I fix CVE-2026-100750?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

How Strix Helps

Related CVEs from 2026

Are you affected by CVE-2026-100750?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST