Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

Updated 24 August: Fabrik 4.7.3 is out, and it is now the version to install

Fabrikar released 4.7.3 on Monday 24 August 2026. It adds no new security fixes: it mops up two regressions that 4.7.2 introduced, links to Fabrik pages from outside websites returning a 404 error, and HEAD requests to Fabrik forms returning 404 while GET returned 200. It has every security fix listed below, and it also ends the guessing that the re-issued 4.7.2 builds caused, because a site showing 4.7.3 has the full fix set. This time the release is in Fabrik's Joomla update feed, so the Joomla updater should offer it on sites with a valid subscription.

Fabrikar released Fabrik 4.7.2 for Joomla on 22 August 2026. It is a security release, and it closes a long list of unauthenticated vulnerabilities in the application and form builder, most of them found and reported by mySites.guru and credited to us by name in Fabrik’s own changelog.

If you run Fabrik on any Joomla site, update now. The current release is 4.7.3, a bug-fix follow-up from 24 August that includes everything 4.7.2 closed. This post is the plain list of what it fixes and what to do. For the back-story of how the 4.7.x line got here, across 4.6.7, 4.6.8, 4.7.0 and 4.7.1, see The Fabrik Fiasco.

TL;DR

  • Fabrik 4.7.2 (22 August 2026) is a security release closing a long list of unauthenticated vulnerabilities: remote code execution, SQL injection, arbitrary file upload, directory listing, database table listing, row disclosure, comment manipulation, path traversal and a heredoc breakout
  • Most of the fixes are credited to mySites.guru in Fabrik’s changelog
  • The Joomla CNA has published seventeen CVE records, and sixteen credit mySites.guru as the finder, four of those at CVSS 10.0
  • Update every Fabrik install to 4.7.3 (24 August 2026), a bug-fix follow-up that has every security fix in 4.7.2 plus repairs for two 404 regressions, and whose version number, unlike the re-issued 4.7.2 builds, tells you exactly what you have
  • Joomla 3 sites cannot install any Fabrik 4 release. There is a manual one-line vendor patch for the calc flaw, offered as-is; plan removal or migration
  • mySites.guru flags every connected Joomla site running Fabrik below 4.7.2

The full list of fixes

The Joomla CNA has published seventeen CVE records for this release, and sixteen of them credit mySites.guru as the finder, four of those at the maximum CVSS 10.0. They are listed here worst first, and every CVE links to its published record. One of the seventeen, the database table listing, appears in no version of Fabrik’s changelog at all; its CVE record is the only public documentation it has.

CVECVSS 4.0What it isReported by
CVE-2026-7660410.0 CriticalUnauthenticated remote code execution via form_php _runPHPmySites.guru
CVE-2026-7660510.0 CriticalUnauthenticated remote code execution via the image element with the eval flagmySites.guru
CVE-2026-7660610.0 CriticalPath traversal in the image elementmySites.guru
CVE-2026-7660710.0 CriticalMissing access check in the download plugin’s foreign-key branchmySites.guru
CVE-2026-779929.5 CriticalHeredoc escaping breakout in the calc elementmySites.guru
CVE-2026-765719.3 CriticalUnauthenticated SQL injection in the list filter condition parametermySites.guru
CVE-2026-766029.3 CriticalUnauthenticated SQL injection in ORDER BY, via a CONCAT( allowlist bypassmySites.guru
CVE-2026-765968.7 HighUnauthenticated table truncation via list.doemptymySites.guru
CVE-2026-765978.7 HighUnauthenticated arbitrary file upload to the web root, in the list email pluginmySites.guru
CVE-2026-765988.7 HighUnauthenticated arbitrary directory listing via onAjax_getFoldersmySites.guru
CVE-2026-765998.7 HighUnauthenticated database table and table-prefix disclosure via ajax_tablesmySites.guru
CVE-2026-770278.6 HighUnauthenticated stored XSS via the JS-Actions featureFabrik
CVE-2026-766006.9 MediumUnauthenticated deletion of any commentmySites.guru
CVE-2026-766016.9 MediumUnauthenticated row reordering in the Order pluginmySites.guru
CVE-2026-766036.9 MediumUnauthenticated row disclosure via form.inlineeditmySites.guru
CVE-2026-766086.9 MediumUnauthenticated disclosure of any commenter’s email addressmySites.guru
CVE-2026-766096.9 MediumUnauthenticated modification of any commentmySites.guru

Fabrik 4.7.2 also re-closed a regression of the original calc-element flaw, CVE-2026-66915, which had been reachable again through a second placeholder substituter; the changelog credits mySites.guru with reporting that regression. The two remote code execution flaws that started this whole run, CVE-2026-66915 in the calc element (reported by Moe Khalilov of LeetProtect Research) and CVE-2026-67282 in the list filter model (reported by Murad Gasimov), were both scored CVSS 4.0 10.0 Critical and fixed earlier in the 4.6.x line.

Just how bad is this?

Honestly, about as bad as an extension vulnerability set gets. Four of these are scored CVSS 10.0, the maximum, and each of the four is reachable by an anonymous visitor with no login: two are direct remote code execution, one is a path traversal in the image element, and one strips out an access check. Add the 9.5 heredoc breakout and the two 9.3 SQL injections and that is seven Critical-rated unauthenticated flaws in a single component, before you count the Highs and the Mediums.

We have been finding and reporting Joomla extension vulnerabilities for years, and a list this long and this severe closed in one release is among the worst we have seen in a long time. If you run Fabrik, treat it that way. Any version below 4.7.2 should be assumed exposed, and the sites most at risk are the ones that publish a Fabrik form or list a visitor can reach without logging in.

What to do

  1. Update every Fabrik install to 4.7.3. It is the current release, published 24 August 2026, and it contains every security fix from 4.7.2 plus repairs for two 404 regressions that 4.7.2 introduced, on links to Fabrik pages from outside websites and on HEAD requests. It needs a valid Fabrik subscription, and this time it is in Fabrik’s Joomla update feed, so the Joomla updater should offer it; if it does not, download it from My Download Files on fabrikar.com. A site showing 4.7.3 has the full fix set, which the version string alone could never tell you on the re-issued 4.7.2 builds.
  2. Test before you deploy. 4.7.x is a real upgrade rather than a point release: it breaks any userAjax calls you use, and sites running the FullCalendar or Paypal plugins need those updated to current versions at the same time. Install and test on a sandbox before a live site.
  3. Joomla 3 sites need a different plan. Fabrik 4 installs on Joomla 4.2 and above and Joomla 5.1 and above only. There is no patched Fabrik 3 release. The vendor has published a manual one-line source patch for the calc flaw in its Announcements forum, offered as-is with no warranty; apply it as a stopgap while you plan removal or migration.
  4. Check exposed sites for compromise. An unauthenticated flaw leaves no login trail, so updating does not tell you whether a site was already hit. Look for unfamiliar administrator accounts, recently modified or unexpected PHP files, and scheduled tasks you did not create.

Finding every Fabrik install across your Joomla sites

The hard part of a list like this is not the fix, it is finding every site that needs it before an attacker does. mySites.guru keeps a live inventory of every extension on every connected Joomla site and flags the ones running an affected version of Fabrik, so this turns into a filtered list rather than an afternoon of logging into control panels. We flag every Fabrik install running any version below 4.7.2.

At a glance

FieldDetail
ComponentFabrik for Joomla (com_fabrik)
VendorFabrikar (fabrikar.com)
TypeMultiple unauthenticated flaws: remote code execution (CWE-94), SQL injection (CWE-89), arbitrary file upload (CWE-434), path traversal (CWE-22), directory listing and access-control failures
CVSS 4.0Up to 10.0 (Critical). Four issues score the maximum 10.0, seven are Critical in all, the rest High and Medium
CVEsSeventeen published by the Joomla CNA, sixteen crediting mySites.guru as finder. The full list, with links and scores, is in the table above
ImpactUnauthenticated remote code execution, full-database SQL injection, arbitrary file upload to the web root, and unauthorised disclosure or modification of data, most with no login, token or user interaction
FinderPhil Taylor, mySites.guru (sixteen of the seventeen)
Affected versionsEvery Fabrik release below 4.7.2
Fixed inFabrik 4.7.2, released 22 August 2026. The current release is 4.7.3 (24 August 2026), a bug-fix follow-up with no security changes

Timeline

  1. We report four unauthenticated issues to Fabrik and the Strike Team

    A list-filter blind SQL injection reading any table, an arbitrary file upload reaching the web root, a list truncation, and a directory listing. A bypass of the SQL injection fix follows on 18 August, and a heredoc breakout on 22 August.

  2. Fabrik 4.7.2 ships as a security release

    It closes a long list of unauthenticated vulnerabilities: remote code execution, SQL injection, arbitrary file upload, directory listing, database table listing, row disclosure, comment manipulation, path traversal and a heredoc breakout. Most of the fixes are credited to mySites.guru by name in Fabrik's own changelog, which is a change from how the 4.6.x releases were handled.

  3. 4.7.3 becomes the version to install

    No new security fixes. It repairs two regressions 4.7.2 introduced, on links to Fabrik pages from outside websites and on HEAD requests, and it is in Fabrik's Joomla update feed, so the updater should offer it.

  4. Seventeen CVE records are published, sixteen crediting mySites.guru

    Four of them score CVSS 4.0 10.0, seven are Critical in all, and the rest High and Medium.

Further Reading

Frequently Asked Questions

What is Fabrik 4.7.2?
Fabrik 4.7.2 is a security release of the Fabrik application and form builder for Joomla, published by Fabrikar on 22 August 2026. It closes a long list of unauthenticated vulnerabilities across the calc element, list filters, the image element, the comment and order plugins, and more. Most of the fixes are credited to mySites.guru in the vendor's own changelog. Every Fabrik version below 4.7.2 should be treated as affected.
What is Fabrik 4.7.3?
Fabrik 4.7.3 is a follow-up bug-fix release published on 24 August 2026, two days after 4.7.2. It contains no new security fixes. It corrects two regressions that 4.7.2 introduced: links to Fabrik pages from outside websites such as Facebook returning a 404 error, and HEAD requests to Fabrik forms returning 404 while GET returned 200. It carries every security fix from 4.7.2, so 4.7.3 is now the version to install, and a site showing 4.7.3 definitively has the full fix set, which the re-issued 4.7.2 builds could not guarantee.
Which vulnerabilities does it fix?
Fabrik 4.7.2 fixes unauthenticated remote code execution in the calc and image elements, unauthenticated SQL injection in the list filters and ORDER BY handling, an unauthenticated arbitrary file upload to the web root, an unauthenticated directory listing, an unauthenticated database table listing, unauthenticated disclosure, modification and deletion of comments, an unauthenticated row disclosure and reordering, a path traversal and a heredoc escaping breakout. The full table is in this post. Most carry no login, no token and no user interaction.
Are these CVEs published?
Yes. The Joomla CNA has published seventeen CVE records for the flaws fixed in this release, and sixteen of them credit mySites.guru as the finder, four of those at the maximum CVSS 10.0. Each CVE in the table below links to its published record.
Which are the most serious?
Four are scored CVSS 4.0 10.0 Critical: CVE-2026-76604 and CVE-2026-76605 are unauthenticated remote code execution, CVE-2026-76606 is a path traversal in the image element, and CVE-2026-76607 is a missing access check in the download plugin. CVE-2026-77992, the heredoc escaping breakout in the calc element, is 9.5, and the two SQL injections, CVE-2026-76571 and CVE-2026-76602, are 9.3. All of them are unauthenticated.
How do I update, and can every site take it?
Update to Fabrik 4.7.3, released 24 August 2026. It contains every security fix from 4.7.2 plus fixes for two 404 regressions, and unlike the re-issued 4.7.2 builds its version number tells you exactly what you have. It needs a valid Fabrik subscription; it is in Fabrik's Joomla update feed, so the Joomla updater should offer it, and it can also be downloaded from fabrikar.com. Fabrik 4 installs on Joomla 4.2 and above and Joomla 5.1 and above only. Joomla 3 sites cannot install any Fabrik 4 release and there is no patched Fabrik 3 release; the vendor has published a manual one-line source patch for the calc flaw for Fabrik 3, offered as-is, and you should plan removal or migration for those sites.
How do I find every Fabrik install across my Joomla sites?
mySites.guru keeps a live inventory of every extension on every connected Joomla site and flags the ones running an affected version of Fabrik, so you get a filtered list rather than checking each site by hand. It flags every Fabrik install running any version below 4.7.2.
EU icon: AI MODIFIEDWritten and edited by a human, with AI assistance. Our approach to AI

What our users say

Ludo
LudoWeb in Montagne
★★★★★

I discovered this platform following an attack linked to the JCE vulnerability. mysites.guru provides all the tools needed to understand what's happening on websites; it's simple to set up, the interface is easy to understand and use, and the tool is very powerful, all for a fair price. In short, huge congratulations and thank you.

Read more reviews
Patrick Valmont
Patrick Valmont
★★★★★

Amazing stuff. Phil did a really good job in getting the service back online and also provided a really detailed report as to what happened and recommendation. His turnaround was fast with clear communication. I would therefore highly recommend his service to anyone.

Read more reviews

Read all 282 reviews →

Ready to Take Control?

Start with a free site audit. No credit card required.

Get Your Free Site Audit