Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Regular Labs fixes security issues across Joomla extensions

Regular Labs has released security updates for roughly 30 Joomla extensions, addressing issues including SSRF, stored XSS and command injection. No CVEs were assigned.

mySites.guru published research on the coordinated 22 July 2026 release, which affects Regular Labs extensions rather than Joomla core. The report does not indicate active exploitation and no formal severity rating was given, but it identifies serious issues reachable in some cases by unauthenticated or low-privilege users.

Priority fixes include:

  • Cache Cleaner 10.0.0, addressing SSRF, OS command injection on SiteGround hosts, path traversal and credential exposure.
  • GeoIP 7.0.0, fixing spoofable client-IP headers and additional SSRF and archive-handling problems.
  • Articles Anywhere 19.0.0, Modules Anywhere 9.0.0 and Users Anywhere 2.0.0, fixing SSRF, stored XSS and unauthorised data exposure.
  • Modals 16.0.0, Tooltips 10.0.0, Keyboard Shortcuts 4.0.0 and Sourcerer 13.0.0, with fixes for stored XSS, arbitrary JavaScript or overly broad code permissions.

Shared Regular Labs Library changes also strengthen AJAX token and permission checks and update an HTTP-message component. Administrators should update every installed Regular Labs extension to its available fixed release and test configuration changes. No CVE identifiers have been assigned to this release.

Originally reported by mySites.guru.