CVE-2026-85195
Received Received - Intake

Privileged Stored XSS in Articles Anywhere Joomla Extension

Vulnerability report for CVE-2026-85195, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Joomla! Project

Description

Joomla Extension - regularlabs.com - Privileged stored XSS via link option in Articles Anywhere extension for Joomla < 20.0.0 - Articles Anywhere accepts link options such as onclick and onmouseover. In affected versions, those options become real HTML event attributes without checking the article author's trust level. The plugin syntax survives Joomla's normal Author content filter because the executable HTML is generated later.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
regularlabs articles_anywhere to 20.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a privileged stored Cross-Site Scripting (XSS) vulnerability in the Articles Anywhere Joomla extension from regularlabs.com. It affects versions before 20.0.0. The issue occurs because the extension accepts link options like onclick and onmouseover without validating the article author's trust level. These options become executable HTML event attributes later, bypassing Joomla's normal content filtering for authors.

Impact Analysis

An attacker with author-level access could inject malicious scripts into articles. When other users view these articles, the scripts execute in their browsers, potentially stealing session cookies, redirecting to phishing sites, or performing actions on behalf of the user. This could lead to unauthorized data access or account compromise.

Compliance Impact

This vulnerability could lead to unauthorized data access or modification, violating GDPR's data protection principles and HIPAA's security requirements for protected health information. It may result in non-compliance due to potential data breaches, unauthorized access, or lack of proper input validation and output encoding.

Mitigation Strategies

Update the Articles Anywhere extension for Joomla to version 20.0.0 or later to address the privileged stored XSS vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-85195. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart