CVE-2026-65754: CWE-22 Improper Limitation of a Pathname to a Restricted Directory in regularlabs.com ReReplacer PRo extension for Joomla
CVE-2026-65754 is a directory traversal vulnerability in the ReReplacer PRo extension for Joomla by regularlabs.com. The issue allows XML include paths to read files outside the intended site directory. This improper limitation of pathname access could lead to unauthorized file disclosure. The vulnerability affects versions 1.0.0 through 15.0.3 of the extension. No official patch or remediation guidance is currently provided, and no known exploits are reported in the wild. The severity is assessed as medium given the potential for unauthorized file access but no further impact details are available.
AI Analysis
Technical Summary
The ReReplacer PRo extension for Joomla suffers from a CWE-22 directory traversal vulnerability (CVE-2026-65754) that allows XML include paths to read files outside the restricted site directory. This improper limitation of pathname access could enable an attacker to access sensitive files on the server. The affected versions are from 1.0.0 up to and including 15.0.3. There is no CVSS score or vendor advisory indicating a patch or mitigation. No known exploits have been reported.
Potential Impact
The vulnerability allows unauthorized reading of files outside the intended site directory, potentially exposing sensitive information stored on the server. The exact impact depends on the files accessible and the server environment, but it does not indicate direct code execution or privilege escalation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the extension and monitor for suspicious activity. Avoid using affected versions in production environments if possible.
CVE-2026-65754: CWE-22 Improper Limitation of a Pathname to a Restricted Directory in regularlabs.com ReReplacer PRo extension for Joomla
Description
CVE-2026-65754 is a directory traversal vulnerability in the ReReplacer PRo extension for Joomla by regularlabs.com. The issue allows XML include paths to read files outside the intended site directory. This improper limitation of pathname access could lead to unauthorized file disclosure. The vulnerability affects versions 1.0.0 through 15.0.3 of the extension. No official patch or remediation guidance is currently provided, and no known exploits are reported in the wild. The severity is assessed as medium given the potential for unauthorized file access but no further impact details are available.
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The ReReplacer PRo extension for Joomla suffers from a CWE-22 directory traversal vulnerability (CVE-2026-65754) that allows XML include paths to read files outside the restricted site directory. This improper limitation of pathname access could enable an attacker to access sensitive files on the server. The affected versions are from 1.0.0 up to and including 15.0.3. There is no CVSS score or vendor advisory indicating a patch or mitigation. No known exploits have been reported.
Potential Impact
The vulnerability allows unauthorized reading of files outside the intended site directory, potentially exposing sensitive information stored on the server. The exact impact depends on the files accessible and the server environment, but it does not indicate direct code execution or privilege escalation.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, restrict access to the extension and monitor for suspicious activity. Avoid using affected versions in production environments if possible.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- Joomla
- Date Reserved
- 2026-07-22T20:46:13.953Z
- Cvss Version
- null
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a61dd679c2644c7f8c8ed4c
Added to database: 07/23/2026, 09:22:47 UTC
Last enriched: 07/23/2026, 10:06:58 UTC
Last updated: 07/23/2026, 10:21:51 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.