PT-2026-63507 · Regularlabs.Com · Sourcerer Extension For Joomla

CVE-2026-64796

·

Published

2026-07-22

·

Updated

2026-07-22

None

No severity ratings or metrics are available. When they are, we'll update the corresponding info on the page.
Free did not require both the article creator and last modifier to be Super Users before executing article PHP. Pro did not consistently enforce configured CSS, JavaScript and PHP permissions across tags, attributes, files and both article owners. PHP include attributes could also escape the configured include folder, and executable script/style variants could bypass detection.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-64796

Affected Products

Sourcerer Extension For Joomla