PT-2026-99781 · Joomla · Modules Anywhere

CVE-2026-100750

·

Published

2026-09-28

·

Updated

2026-09-30

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Modules Anywhere versions 1.5.0 through 9.0.5
Description Modules Anywhere Pro allows additional attributes on a module tag to replace arbitrary parameters of the selected module, a feature enabled by default. These overrides are applied without verifying the author of the content containing the tag. The impact depends on how the selected module processes the replaced parameter. For instance, the Joomla core Feed module is affected via its rssurl parameter, which the server opens and allows to contain both local file and network URLs, potentially leading to Local File Inclusion (LFI) or Server-Side Request Forgery (SSRF).
Recommendations Update Modules Anywhere to a version later than 9.0.5.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100750

Affected Products

Modules Anywhere