Joomla Extensions
3 articles tagged Joomla Extensions, newest first.
Readers also browse

iCagenda 4.0.12 fixes an unauthenticated SQL injection
CVE-2026-67365 is an unauthenticated SQL injection in the iCagenda Calendar module for Joomla, scored 9.2 Critical. Fixed in 4.0.12.

Sourcerer 14 and 15 did not fix CVE-2026-74253. 16.0.0 does.
Sourcerer 14 and 15 were both published as the fix for CVE-2026-74253 and neither closed it. It is exploited in the wild. Update now to 16.0.0.

Regular Labs Patched Its Whole Joomla Extension Catalogue at Once
Regular Labs shipped a security-hardening update across its Joomla extension range on 22 July 2026: SSRF, command injection, stored XSS and more. No CVEs.