regularlabs.com vulnerabilities
14 CVEs tracked
In our recent reports, Regular Labs Joomla extensions have appeared prominently due to critical vulnerabilities. The main risks involve Path Traversal (CVE-2026-64872) and SSRF (CVE-2026-64873) in the `Cache Cleaner Pro` extension, as well as credential leakage (CVE-2026-65430) and IP spoofing (CVE-2026-64875) in the `GeoIP` extension. These flaws could allow unauthorized access to internal network services, exposure of sensitive credentials, and bypassing of security controls. Defenders should immediately apply updates for the listed CVEs and pay special attention to preventing credential exposure in administrative requests.
Azərbaycanca: Son hesabatlarımızda Regular Labs Joomla genişləndirmələri kritik zəifliklər səbəbilə tez-tez qeyd olunur. Əsas risklər `Cache Cleaner Pro` genişləndirməsində aşkarlanan Path Traversal (CVE-2026-64872) və SSRF (CVE-2026-64873), həmçinin `GeoIP` genişləndirməsində kredensial sızması (CVE-2026-65430) və IP spoofing (CVE-2026-64875) zəiflikləridir. Bu zəifliklər daxili şəbəkə xidmətlərinə icazəsiz giriş, həssas etimadnamələrin ifşası və təhlükəsizlik mexanizmlərindən yan keçməyə səbəb ola bilər. Müdafiəçilər sadalanan CVE-lər üzrə dərhal yeniləmələri tətbiq etməli və administrator sorğularında kredensialların ifşa olunmasına qarşı xüsusilə diqqətli olmalıdır.
This vendor's CVEs14
- CVE-2026-65756EPSS 0.25%
- CVE-2026-65755EPSS 0.24%
- CVE-2026-65754EPSS 0.34%
- CVE-2026-65713EPSS 0.22%
- CVE-2026-65712EPSS 0.14%
- CVE-2026-65431EPSS 0.38%
- CVE-2026-65430EPSS 0.24%
- CVE-2026-64876EPSS 0.13%
- CVE-2026-64875EPSS 0.21%
- CVE-2026-64874EPSS 0.29%
- CVE-2026-64873EPSS 0.27%
- CVE-2026-64872EPSS 0.22%
- CVE-2026-64871EPSS 0.09%
- CVE-2026-64799EPSS 0.31%
This hub is built from skopnix's own reporting on regularlabs.com: the overview is AI-written from that coverage and every CVE links to its grounded explainer. KEV status comes from CISA's Known Exploited Vulnerabilities catalog and EPSS from FIRST — vendor, version and score details are never invented.