CVE
6 articles tagged CVE, newest first.

14 More Joomla 3 Security Fixes, Each Tested on a Real 3.10.12 Site
Joomla 5.4.9 fixed 16 core issues. We backported every one reaching Joomla 3 to the mySites.guru one-click patch tool, each proved on a real 3.10.12 site.

Balbooa Forms 2.4.3.4 Fixes Five Security Issues
Balbooa Forms 2.4.3.4 fixes five CVEs in the Joomla form builder, led by a 9.5 unauthenticated RCE. Every version below 2.4.3.4 is affected. Update now.

AcyMailing 11.1.0 Fixes Two Security Flaws
AcyMailing 11.1.0 fixes a mailbox file write and a file deletion flaw, now CVE-2026-94132 (9.5 Critical) and CVE-2026-94131, both filed under Bug fixes.

iCagenda 4.0.12 fixes an unauthenticated SQL injection
CVE-2026-67365 is an unauthenticated SQL injection in the iCagenda Calendar module for Joomla, scored 9.2 Critical. Fixed in 4.0.12.

We Are Not the Only Ones Auditing Joomla Extensions
Two Joomla extension flaws went public via the Joomla CNA: a SQL injection in JoomCCK and a stored XSS in ChronoForms. Neither was ours. Update now.

Nineteen and Counting: Joomla Extension Vulnerabilities We Found and Disclosed in a Month
Nineteen Joomla extension vulnerabilities mySites.guru found and disclosed in a month, with CVE ids, CVSS scores and the version that fixes each one.