SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65754

HIGH · CVSS 7.5 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The ReReplacer Pro extension for Joomla is vulnerable due to insecure path handling, allowing attackers to exploit XML include paths to read files outside the site directory. This could lead to unauthorized access to sensitive information and potential data leakage. Joomla site administrators using this extension should prioritize patching or mitigating this vulnerability to protect their systems from potential exploitation.

CVE
CVE-2026-65754
Severity
HIGH
CVSS
7.5
EPSS
0.34%

Original NVD Description

Joomla Extension - regularlabs.com - Insecure path handling in ReReplacer Pro extension - ReReplacer XML include paths could read files outside the site directory.