PT-2026-99782 · Joomla · Tabs & Accordions
CVE-2026-100751
·
Published
2026-09-28
·
Updated
2026-09-30
CVSS v4.0
7.5
High
| Vector | AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:N/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
Tabs & Accordions (Pro) versions 2.3.0 through 3.1.0
Description
This issue allows privileged stored Cross-Site Scripting (XSS), a condition where a malicious script is permanently stored on the server and executed in the browser of other users. The extension accepts a URL option for an item and writes it to a generated
data-rlta-url attribute. When the item is activated, the browser code passes this value to the window.open() function. Because the software does not reject browser URL schemes that execute JavaScript, it creates executable browser behavior during article rendering, bypassing the standard filtering performed by Joomla.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Tabs & Accordions