Joomla administrators using Regular Labs Modules Anywhere or Tabs & Accordions should update to versions 10.0.0 and 3.2.0 respectively as a prudent security measure. However, two CVE identifiers initially associated with those releases are officially assigned to Event Gallery for Joomla, so administrators need to separate the update action from the unresolved CVE mapping.

Regular Labs Modules Anywhere 10.0.0 and Tabs & Accordions 3.2.0 are security-focused extension updates that Joomla administrators should schedule promptly. The immediate operational advice is straightforward: update the extensions, test the pages that depend on them, and keep a verified rollback path. The security-record attribution behind the releases, however, requires care: CVE-2026-97164 and CVE-2026-97165 currently identify vulnerabilities in Event Gallery for Joomla by svenbluege.de, not in the two Regular Labs extensions.

What Joomla administrators should do now

For sites running the affected Regular Labs extensions, treat the available releases as a normal priority security-maintenance task. Update Modules Anywhere to 10.0.0 and Tabs & Accordions to 3.2.0. These are third-party Joomla extension updates, not Joomla core updates.

Do not delay the updates while waiting for the CVE attribution to be clarified. A missing or disputed CVE reference does not make an extension security release unimportant; it means administrators should avoid attaching unverified technical details, severity ratings, or exploitation claims to that release.

  1. Confirm where the extensions are installed. Check every Joomla 4, Joomla 5, and Joomla 6 site in the portfolio, including staging, multilingual, and less frequently maintained sites.
  2. Take and validate a backup. Retain a recent restorable copy of the database and site files before making changes. A backup is useful only when the team knows it can restore it.
  3. Update Modules Anywhere to 10.0.0 and Tabs & Accordions to 3.2.0. Use the site’s established extension-update process and record the previous installed version for rollback planning.
  4. Test the public-facing output. Review pages, articles, custom HTML modules, and template positions that use either extension. For Modules Anywhere, give extra attention to places where module settings are overridden by the insertion context.
  5. Clear appropriate caches and retest as a visitor. Test in a private browser session and on relevant device widths, especially for accordion and tab layouts.
  6. Document the change. Agencies should record the update, tests performed, and any exceptions in the client’s maintenance log.

If a production site cannot be updated immediately, reduce exposure by limiting administrator access to trusted staff, ensuring the Joomla administrator area is protected according to the site’s access policy, and scheduling a tested maintenance window. These are compensating controls, not substitutes for applying a security update.

Why the CVE mapping needs correction

A CVE is an identifier for a specific publicly reported vulnerability. It must be tied to the correct product before it can reliably drive patching, ticketing, compliance records, or risk reporting.

Regular Labs initially associated CVE-2026-97165 with Modules Anywhere and CVE-2026-97164 with Tabs & Accordions. That mapping conflicts with the official published CVE records. The CVE record for CVE-2026-97164 and the CVE record for CVE-2026-97165 assign both identifiers to Event Gallery for Joomla by svenbluege.de.

Therefore, administrators should not list either CVE as a confirmed identifier for Modules Anywhere 10.0.0 or Tabs & Accordions 3.2.0. The correct CVE identifiers for the Regular Labs issues are not currently confirmed and remain pending clarification from the Joomla Security Strike Team and Regular Labs.

This distinction matters beyond terminology. Incorrect CVE mapping can cause vulnerability scanners, client reports, internal asset registers, and patch-management systems to show the wrong product as exposed or remediated. Update the Regular Labs extensions as advised, but keep their change records separate from the Event Gallery CVEs until authoritative records establish a different mapping.

The initial association was reported in an original disclosure roundup. The CVE records are the stronger source for product attribution and take precedence where the accounts conflict.

Verified Joomla extension vulnerabilities in Event Gallery

The two verified CVEs concern Event Gallery for Joomla, not the Regular Labs extensions. They are useful context for administrators who operate Event Gallery, and they illustrate why accurate product identification is essential.

ExtensionCVEIssue and authenticationAffected-version evidenceRecommended versionCVSS 4.0CISA KEV status
Event Gallery for JoomlaCVE-2026-97164Authenticated path traversal that can enable arbitrary path deletion through a cache-clearing functionStructured data lists versions 1.0.0 through 6.0.0. The CVE description refers to versions earlier than 6.5.0, but the record does not explicitly state a fixed version.Monitor vendor guidance and move to a confirmed non-affected version when identified.7.0 HIGHNot listed in the evidence catalog
Event Gallery for JoomlaCVE-2026-97165Reflected cross-site scripting and open redirect; no authentication is required for the described issueStructured data lists versions 1.0.0 through 6.0.0. The CVE description refers to versions earlier than 6.5.0, but the record does not explicitly state a fixed version.Monitor vendor guidance and move to a confirmed non-affected version when identified.5.3 MEDIUMNot listed in the evidence catalog

Do not infer an Event Gallery fixed version from the wording of the CVE descriptions. Although the descriptions reference versions earlier than 6.5.0, the structured affected range and available evidence do not explicitly designate a fixed release. Administrators should review the Event Gallery vendor source and Joomla security information, then update once a non-affected version is clearly confirmed.

CVE-2026-97164: authenticated deletion risk

CVE-2026-97164 has a CVSS 4.0 score of 7.0 (HIGH). The record describes an authenticated path traversal issue in an Event Gallery cache-clearing task. A user with sufficient permissions could cause recursive deletion of directories writable by the web server. For an Event Gallery site, access to administration and cache-clearing functions should be restricted to trusted, necessary accounts, and tested backups should be available.

CVE-2026-97165: reflected XSS and redirect risk

CVE-2026-97165 has a CVSS 4.0 score of 5.3 (MEDIUM). The record describes reflected cross-site scripting and an open redirect involving a return value placed into a back link without adequate validation. Until a confirmed non-affected version is available, reduce unnecessary exposure of relevant Event Gallery views to untrusted users where feasible and consider carefully tuned web application firewall rules as an additional defensive layer.

Severity, NVD status, and confirmed exploitation

Severity scoring and observed exploitation answer different questions. CVSS estimates the technical characteristics and potential impact of a vulnerability. It does not prove that attackers are using it. Conversely, a CISA Known Exploited Vulnerabilities listing is evidence that a vulnerability has been observed being exploited, but it is not a replacement for assessing a site’s own exposure.

As reflected in the evidence catalog version 2026.09.27, neither CVE-2026-97164 nor CVE-2026-97165 appears in the CISA Known Exploited Vulnerabilities catalog. Exploitation is not confirmed by the available evidence, and there is no verified evidence of ransomware use. This is a reason to communicate calmly and accurately, not a reason to postpone maintenance.

The NVD entry for CVE-2026-97164 and the NVD entry for CVE-2026-97165 are both in the Received state. That means full NVD analysis is still pending. Technical details, version interpretation, and scoring information can be refined as analysis progresses. The CVSS values in this article are explicitly CVSS 4.0 values; they are not CVSS 3.1 scores and should not be converted or represented as such.

A practical maintenance workflow for agencies and site owners

Security updates are safest when they are repeatable. For one site, that may mean a short checklist; for an agency, it should mean an inventory, maintenance windows, standard testing, and evidence of completion.

  • Inventory extensions by site. Record whether each site uses Modules Anywhere, Tabs & Accordions, Event Gallery, or none of them. Do not assume that a standard agency build is identical across clients.
  • Prioritise the confirmed update path. Apply the Regular Labs updates where installed. Keep this work separate from Event Gallery remediation because the confirmed CVEs belong to Event Gallery.
  • Validate behaviour, not only version numbers. Check inserted modules, access-controlled content, tab navigation, accordions, responsive presentation, multilingual pages, and cached pages. Test both a normal user journey and key administrative editing workflows.
  • Use a rollback plan. Preserve the pre-update backup and note the prior package version. If an update introduces a functional regression, restore through the documented process, restrict the affected feature where possible, and investigate before attempting another deployment.
  • Apply least privilege. Give Joomla and extension administration access only to people who need it. Review inactive accounts and remove permissions no longer required.
  • Protect recovery capability. Maintain backups outside the production environment and periodically test restores. This is particularly relevant to a deletion-capable issue such as CVE-2026-97164.
  • Review security notices regularly. Monitor extension update notifications and authoritative security advisories as part of scheduled Joomla maintenance rather than waiting for social-media reports.

For Event Gallery users, the immediate sequence is to identify the installed version, restrict access to Event Gallery administration and cache-clearing features, verify backups, monitor vendor guidance, and update to a clearly identified non-affected version when that guidance becomes available. For Regular Labs users, the immediate sequence is to update Modules Anywhere and Tabs & Accordions, test dependent content, and track any future authoritative clarification of the associated CVE identifiers.

Sources and record status

The following records were used for the product attribution, technical summaries, scores, and analysis-status qualifications in this article.

Add comment

By submitting a comment, you agree to our Comment Policy and Privacy Policy. Please keep comments respectful, relevant, and free from spam or promotional content. Your name and comment may be displayed publicly, while your email address will not normally be published. Technical information, including your IP address, may be processed for moderation, security, and spam prevention.

Submit