Joomla Extension - regularlabs.com - Privileged stored XSS via class option in Quick Index extension for Joomla < 5.0.5 - Quick Index inserts configurable class values into generated HTML without escaping them for an HTML attribute. A crafted value can close the intended class attribute and introduce a new attribute. Joomla's content filter cannot reliably prevent this because Quick Index creates the executable HTML after the authored plugin syntax was filtered.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://www.regularlabs.com/ |
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-14 07:17
Updated : 2026-09-16 19:28
NVD link : CVE-2026-85190
Mitre link : CVE-2026-85190
CVE.ORG link : CVE-2026-85190
JSON object : View
Products Affected
No product.
CWE
CWE-79
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
