CVE-2026-64799

CVE-2026-64799: Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions

Vendor Regularlabs.com
Product Articles Anywhere Pro extension for Joomla
Weakness CWE-918 · SSRF
Published July 23, 2026
Last update July 23, 2026

CVSS base score

What the vulnerability does

01Description

Joomla Extension - regularlabs.com - SSRF via remote image downloads in Articles Anywhere and Users Anywhere extensions - Content-controlled image URLs could request private or reserved network services, follow unsafe redirects and save responses without validating that they were images. This could result in SSRF, internal-data access or writing attacker-controlled files into a web-accessible folder.

Key dates

02Disclosure timeline

July 23, 2026 CVE published
July 23, 2026 Record updated

Related vulnerabilities

04Related CVE