Skip to main content
mySites.guru
4+ live

Joomla extension security alerts (26 Aug) Sourcerer 16.0.0Fabrik 4.7.2ZOO: unauth RCEJCE 2.9.99.10

RCE

7 articles tagged RCE, newest first.

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

Fabrik 4.7.2 for the Joomla extension closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Update now.

The Fabrik Fiasco: Announced, Restricted, Relabelled

The Fabrik Fiasco: Announced, Restricted, Relabelled

Two CVSS 10.0 RCEs in the Fabrik Joomla extension, and a chaotic run of security releases since. The vendor has moved past 4.7.0; be on 4.7.2.

Another 23 Critical Security Vulnerabilities in Gridbox for Joomla

Another 23 Critical Security Vulnerabilities in Gridbox for Joomla

Balbooa asked mySites.guru to audit Gridbox for Joomla. We found 23 vulnerabilities, including a pre-auth RCE, some exploited already. Fixed in 2.20.2.

PageBuilder CK RCE fixed - again - correctly this time

PageBuilder CK RCE fixed - again - correctly this time

PageBuilder CK's 3.6.0 fix for its file-upload RCE (CVE-2026-56290) added just a login check; any Editor could still run code. Fixed in 3.6.3. Be on 3.6.5.

PageBuilder CK File Upload RCE - June 2026

PageBuilder CK File Upload RCE - June 2026

PageBuilder CK below 3.6.0 lets anyone upload and run a file on your Joomla site, no login. CVE-2026-56290, CVSS 10.0, exploited in the wild. Update to 3.6.0.

Zero Day Vulnerability Found in iCagenda Joomla Extension

Zero Day Vulnerability Found in iCagenda Joomla Extension

mySites.guru found and confirmed an unauthenticated upload giving remote code execution on Joomla 6 sites running iCagenda. Fixed same-day in 4.0.8.

SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins

SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins

An unauthenticated upload in the SP Page Builder Joomla extension gives remote code execution and creates hidden Super User accounts. Fixed in 6.6.2.

Browse every article