On July 22, 2026, Regular Labs developer (Peter van Westen) released a large-scale security update affecting more than 30 extensions simultaneously. Among them are popular extensions such as Advanced Module Manager, Articles Anywhere, Sourcerer, Cache Cleaner, Modals, Tooltips, GeoIP, and many others.

The update was released quietly — without a separate announcement, only [SECURITY FIX] entries in each extension's changelog. The vulnerabilities have been assigned CVE-2026-63265 (insufficient CSRF token and permission checks) and CVE-2026-65756 (XSS in Keyboard Shortcuts). This update is critically important for all sites using extensions from Regular Labs.

Understanding the Threat: What Was Fixed?

This update addresses several classes of vulnerabilities affecting nearly all of the developer's extensions:

  • Insufficient CSRF Token and Permission Checks (CVE-2026-63265): Privileged AJAX endpoints did not always require a valid CSRF token and appropriate permissions. This allowed an authenticated user with low privileges, or through a CSRF attack, to perform actions beyond their authority.
  • XSS Vulnerabilities (CVE-2026-65756): In some extensions, such as Keyboard Shortcuts, the configuration accepted arbitrary inline JavaScript, allowing malicious code injection.
  • CRLF Injection in HTTP Requests: The PSR-7 library used for outgoing HTTP requests was updated, closing the possibility of header injection through line break characters.

The most serious fixes affected the following extensions:

  • Cache Cleaner: SSRF (Server-Side Request Forgery to internal networks), OS command injection on SiteGround hosting, Path Traversal, exposure of CDN credentials in URLs.
  • GeoIP: client IP header spoofing, allowing bypass of GeoIP access restrictions.
  • Articles Anywhere, Modules Anywhere, Users Anywhere: SSRF via external images, stored XSS, exposure of hidden content and authentication data.
  • Sourcerer: restriction of PHP execution in articles to Super Administrators only.

Who Is at Risk?

All sites running Regular Labs extensions with versions below the fixed versions listed are at risk.

Critical Warning for Joomla 3 Owners!
All latest versions of Regular Labs extensions require Joomla 4, 5, or 6 and do not support Joomla 3.

If your site is running Joomla 3, you will not be able to update Regular Labs extensions to the secure versions. This means your site remains vulnerable. The only solution is migration to Joomla 5 or 6, after which updating the extensions will become possible.

Extensions with Joomla 3 support no longer receive security updates.

How to Fix It: Step-by-Step Instructions

Step 1: Check Which Regular Labs Extensions Are Installed

Use Regular Labs Extension Manager — a special component that allows you to:

  • View all installed Regular Labs extensions.
  • Check their versions and available updates.
  • Install and update all extensions with one click.

If you have PRO versions, you need to enter your Download Key in the Extension Manager settings.

Step 2: Update All Regular Labs Extensions

Through the Regular Labs Extension Manager, click «Update All» — this will update all installed extensions to the latest versions.

Step 3: Update Joomla to the Latest Version

If you are still on Joomla 3, plan your migration to Joomla 5 or 6. Only after this will you be able to update Regular Labs extensions to the secure versions.

Migration process:

  1. Update Joomla 3 to the latest version 3.10.
  2. Update all Regular Labs extensions to the latest versions for Joomla 3.
  3. Perform migration to Joomla 4, then to Joomla 5 or 6.
  4. Update PHP to version 8.1 or higher.
  5. Reinstall the latest versions of Regular Labs extensions for the new Joomla version.

How We Can Help

Site Maintenance Services
We offer a comprehensive Joomla site maintenance service, which includes:

  • Updating all extensions, including PRO versions from Regular Labs (using our license).
  • Migration from Joomla 3 to the latest versions.
  • Checking sites for signs of compromise.
  • Configuring additional security measures.

If you are unsure about updating your site yourself, or if you don't have a subscription for Regular Labs PRO versions — contact us! We will handle the update for you.

Important!
If your site has already been compromised, a simple update will not remove hidden administrator accounts or malicious code. After updating, be sure to check your site for backdoors and suspicious files. If you have any doubts — contact us for professional assistance!

Submit a request List of services