CVE-2026-88853
Received Received - Intake

Privileged Stored XSS in Modals Pro Joomla Extension

Vulnerability report for CVE-2026-88853, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-14

Assigner: Joomla! Project

Description

Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed. Affected versions do not distinguish trusted extension configuration from event code supplied in ordinary article content. A lower-privileged author can therefore use a documented executable feature which should be reserved for trusted authors.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-14
Generated
2026-09-14
AI Q&A
2026-09-14
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
regularlabs modals_pro to 17.0.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-79 The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a privileged stored Cross-Site Scripting (XSS) flaw in the Modals Pro extension for Joomla versions below 17.0.0. It occurs because the extension supports JavaScript event handlers like on-open and on-closed but fails to properly validate event code in article content. A lower-privileged author can inject malicious scripts that execute when the modal is opened or closed, bypassing intended access controls.

Detection Guidance

This vulnerability involves a stored XSS in the Modals Pro extension for Joomla versions below 17.0.0. To detect it, inspect Joomla installations for the Modals Pro extension and verify its version. Check for unauthorized JavaScript events in article content or extension configurations that use documented event handlers like on-open or on-closed.

Impact Analysis

An attacker with author-level access could exploit this to execute arbitrary JavaScript in the context of other users, potentially stealing session cookies, redirecting to malicious sites, or performing actions on behalf of users. This could lead to unauthorized data access, account takeover, or defacement of Joomla sites using the vulnerable extension.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR (data protection) or HIPAA (health information security) by enabling unauthorized access to sensitive user data. If exploited, it may lead to data breaches, triggering mandatory breach notifications and potential fines under these regulations.

Mitigation Strategies

Immediately update the Modals Pro extension to version 17.0.0 or later. Review and remove any suspicious JavaScript event handlers in article content or extension configurations. Restrict author privileges to prevent unauthorized use of executable features.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-88853. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart