SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-74253

CRITICAL · CVSS 10 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-17 · Last synced 2026-09-16

CyberRota Analysis

AI-Generated

The Regular Labs Sourcerer extension for Joomla versions prior to 14.0.0 is vulnerable to unauthenticated remote code execution due to improper handling of reflected user input in {source} blocks. This critical vulnerability allows attackers to execute arbitrary code on the server, potentially compromising the entire Joomla installation. Organizations using affected versions of this extension should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-74253
Severity
CRITICAL
CVSS
10
EPSS
0.32%

Original NVD Description

Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 - Regular Labs Sourcerer before 16.0.0 processes {source} blocks found in Joomla’s final rendered HTML without reliably determining where that code originated.