PT-2026-99782 · Joomla · Tabs & Accordions

CVE-2026-100751

·

Published

2026-09-28

·

Updated

2026-09-30

CVSS v4.0

7.5

High

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Tabs & Accordions (Pro) versions 2.3.0 through 3.1.0
Description This issue allows privileged stored Cross-Site Scripting (XSS), a condition where a malicious script is permanently stored on the server and executed in the browser of other users. The extension accepts a URL option for an item and writes it to a generated data-rlta-url attribute. When the item is activated, the browser code passes this value to the window.open() function. Because the software does not reject browser URL schemes that execute JavaScript, it creates executable browser behavior during article rendering, bypassing the standard filtering performed by Joomla.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-100751

Affected Products

Tabs & Accordions