Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Regular Labs patches Joomla extensions across its catalogue

Regular Labs has released security fixes across roughly 30 Joomla extensions, addressing issues including SSRF, command injection and stored XSS. Administrators should update now.

Research published by mySites.guru says the 22 July 2026 release also hardens the shared Regular Labs Library, including privileged AJAX checks and an HTTP request-handling fix. The issues affect Regular Labs extensions rather than Joomla core.

No CVE identifiers were assigned to the fixes, and the write-up does not identify active exploitation. The reported problems include unauthenticated and low-privilege issues, as well as administrator-side weaknesses.

  • Cache Cleaner 10.0.0 fixes SSRF, SiteGround command injection, path traversal and credential exposure.
  • GeoIP 7.0.0 addresses spoofed client-IP headers, SSRF, credential exposure and unsafe archive extraction.
  • Articles Anywhere 19.0.0, Modules Anywhere 9.0.0 and Users Anywhere 2.0.0 fix SSRF, stored XSS and unauthorised data exposure.
  • Modals 16.0.0, Tooltips 10.0.0 and Keyboard Shortcuts 4.0.0 address stored XSS, path traversal or arbitrary JavaScript execution.
  • Sourcerer 13.0.0 restricts PHP in articles to Super Users.

Administrators should update every installed Regular Labs extension to its latest release, prioritising the extensions above, and test any affected functionality after updating.

Originally reported by mySites.guru.