SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-88853

HIGH · CVSS 7.5 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-14 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The Modals Pro extension for Joomla versions prior to 17.0.0 is vulnerable to a stored cross-site scripting (XSS) attack due to improper handling of JavaScript event handlers, allowing lower-privileged users to inject malicious scripts. This vulnerability can lead to unauthorized actions and data exposure, posing a significant risk to website integrity and user security. Joomla site administrators and developers using the affected extension should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-88853
Severity
HIGH
CVSS
7.5
EPSS
0.25%
Java

Original NVD Description

Joomla Extension - regularlabs.com - Privileged stored XSS via event handler option in Modals Pro extension for Joomla < 17.0.0 - Modals Pro intentionally supports JavaScript Events such as on-open and on-closed. Affected versions do not distinguish trusted extension configuration from event code supplied in ordinary article content. A lower-privileged author can therefore use a documented executable feature which should be reserved for trusted authors.