Каталог CVE

Разработчик: regularlabs.com

Каталог

Все известные уязвимости

Статус «активна» означает, что запись опубликована в 2026 году. Он не заменяет проверку версии и официального исправления.

Сбросить

Найдено: 30

Разработчик: regularlabs.com
Критическая CVSS 9.8

CVE-2026-64796

Разработчикregularlabs.com

various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consisten…

22.07.2026 Требует внимания
Средняя CVSS 5.4

CVE-2026-64795

Разработчикregularlabs.com

XSS vectors in tag-provided inputs in various Regular Labs extensions - Tag-provided custom HTML, module content/title overrides and decoded modal or tooltip values could execute unsafe mar…

22.07.2026 Активна
Средняя CVSS 6.5

CVE-2026-64794

Разработчикregularlabs.com

restricted user-data exposure in Users Anywhere and Articles Anywhere extensions - User tags, filters and conditions allowed access to insufficiently restricted user fields. Crafted content…

22.07.2026 Активна
Критическая CVSS 9.1

CVE-2026-64793

Разработчикregularlabs.com

Content access and publication bypass in Articles Anywhere and Modules Anywhere extensions - Content tags could use ignore flags or property overrides to render restricted or unpublished ar…

22.07.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-64792

Разработчикregularlabs.com

disclosure of restricted content via search index in various Regular Labs extensions - Smart Search indexing could render generated content using the indexing administrator’s identity inste…

22.07.2026 Требует внимания
Высокая CVSS 8.8

CVE-2026-64791

Разработчикregularlabs.com

Inconsistent CSRF token checks / privilege checks in Regular Labs Extension Manager - Administrator routes and install/update/uninstall processing did not consistently enforce component-man…

22.07.2026 Требует внимания
Высокая CVSS 8.8

CVE-2026-63685

Разработчикregularlabs.com

Authorization bypass in DB Replacer extension - Administrator routes and replacement requests did not consistently require Super User permission and a valid token. An unauthorized backend u…

22.07.2026 Требует внимания
Высокая CVSS 8.8

CVE-2026-63684

Разработчикregularlabs.com

Inconsistent CSRF token checks / privilege checks in various admin/import/export actions of multiple Regular Labs extension - Administrator actions, editor popups and import/export requests…

22.07.2026 Требует внимания
Высокая CVSS 7.5

CVE-2026-63683

Разработчикregularlabs.com

Client IP spoofing vulnerability in Regular Labs conditions manager - IP and GeoIP conditions trusted spoofable forwarded headers, allowing remote clients to bypass location-based rules.

22.07.2026 Требует внимания
Средняя CVSS 4.8

CVE-2026-63281

Разработчикregularlabs.com

XSS vulnerability in Regular Labs conditions manager - Stored condition values could also execute HTML/JavaScript in administrator summaries.

22.07.2026 Активна
Высокая CVSS 8.8

CVE-2026-63280

Разработчикregularlabs.com

Inconsistent CSRF token checks / privilege checks in Regular Labs conditions manager - Conditions administration did not consistently enforce tokens and component/mapped-item permissions.

22.07.2026 Требует внимания
Высокая CVSS 8.0

CVE-2026-63265

Разработчикregularlabs.com

Inconsistent CSRF token checks / privilege checks in various Regular Labs extension AJAX endpoints - Privileged Regular Labs AJAX endpoints did not consistently require valid CSRF tokens, m…

22.07.2026 Требует внимания