What is CVE-2026-65754?
This vulnerability involves insecure path handling in the ReReplacer Pro extension for Joomla. XML include paths can be exploited to read files outside the site directory. It is recommended to update the extension to the latest version to mitigate this issue.
Azərbaycanca: Bu boşluq Joomla üçün ReReplacer Pro əlavəsində təhlükəli yol idarəetməsinə (insecure path handling) imkan verir. XML faylları daxil edilərkən saytın əsas qovluğundan kənardakı fayllar oxuna bilər. Bu problemi aradan qaldırmaq üçün əlavəni ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-22; shared vendor: regularlabs.com
FAQ2
What software is affected by CVE-2026-65754?
This vulnerability affects the ReReplacer Pro extension for Joomla.
How should CVE-2026-65754 be mitigated?
To mitigate this issue, it is recommended to update the ReReplacer Pro extension to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.