CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100751

UNKNOWNCVSS 0NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

Joomla Extension - regularlabs.com - Privileged stored XSS via data-rlta-url attributes in Tabs & Accordions (Pro) 2.3.0 - 3.1.0 - Tabs & Accordions Pro accepts a url option for an item and writes it to a generated data-rlta-url attribute. The browser code passes that value to window.open() when the

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-100751 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-100751

UNKNOWNCVSS 0NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

Joomla Extension - regularlabs.com - Privileged stored XSS via data-rlta-url attributes in Tabs & Accordions (Pro) 2.3.0 - 3.1.0 - Tabs & Accordions Pro accepts a url option for an item and writes it to a generated data-rlta-url attribute. The browser code passes that value to window.open() when the

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]