CVE-2026-63684
N/A
N/A
Summary
Administrator actions, editor popups and import/export requests lacked consistent token, item-permission and input-validation checks. Unauthorized backend users or CSRF attacks could expose, create or modify extension configuration and items.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| regularlabs.com | Content Templater extension for Joomla | 1.0.0-13.0.0 | affected |
| regularlabs.com | ReReplacer extension for Joomla | 1.0.0-15.0.3 | affected |
| regularlabs.com | Snippets extension for Joomla | 1.0.0-9.3.10 | affected |
Weaknesses
- CWE-352: CWE-352 Cross-Site Request Forgery (CSRF)
- CWE-284: CWE-284 Improper Access Control
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.