SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-64796

CRITICAL · CVSS 9.8 EPSS 0.29%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

The Sourcerer extension for Joomla is vulnerable due to multiple code injection vectors that allow unauthorized execution of PHP code without proper user permissions. This critical vulnerability can lead to arbitrary code execution, potentially compromising the integrity and security of affected systems. Organizations using the Sourcerer extension, particularly those managing sensitive data or critical applications, should prioritize immediate remediation to mitigate the risk of exploitation.

CVE
CVE-2026-64796
Severity
CRITICAL
CVSS
9.8
EPSS
0.29%
Java

Original NVD Description

Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.