Regularlabs
Regularlabs Sourcerer: vulnerabilities and CVEs
Regularlabs Sourcerer has 3 published vulnerabilities, 2 of them in the last 12 months. 3 are rated critical and 0 are listed by CISA as actively exploited.
CVEs3
Last 12 months2
Critical3
Actively exploited0
All vulnerabilities in the catalogue →⭐ Follow this technology
Latest vulnerabilities
| CVE | Severity | EPSS | Active exploitation | Published | Description |
|---|---|---|---|---|---|
| CVE-2026-74253 | Critical (10) | 0.44% | — | Aug 17, 2026 | Joomla Extension - regularlabs.com - Unauthenticated RCE through unverified reflected user input in Sourcerer < 16.0.0 - Regular Labs Sourcerer before 16.0.0 processes {source} blocks found in Joomla’s final rendered… |
| CVE-2026-64796 | Critical (9.8) | 0.51% | — | Jul 22, 2026 | Joomla Extension - regularlabs.com - various code injection vectors in Sourcerer extension - Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not… |
| CVE-2025-22204 | Critical (9.8) | 0.78% | — | Feb 4, 2025 | Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability. |
🎯 How it gets exploited (ATT&CK techniques)
Number of CVEs of this technology mapped to each exploitation or primary-impact technique.