Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

RCE

8 articles tagged RCE, newest first.

OS CCK 8.3.16 for Joomla Fixes a No-Login PHP Upload and an SQL Injection, but the Updater Still Offers 8.3.14

OS CCK 8.3.16 for Joomla Fixes a No-Login PHP Upload and an SQL Injection, but the Updater Still Offers 8.3.14

OS CCK for Joomla before 8.3.16 had a no-login PHP upload (CVE-2026-102427) and SQL injection (CVE-2026-102428). The updater won't offer the fix.

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

Fabrik 4.7.2 for the Joomla extension closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Update now.

The Fabrik Fiasco: Announced, Restricted, Relabelled

The Fabrik Fiasco: Announced, Restricted, Relabelled

Two CVSS 10.0 RCEs in the Fabrik Joomla extension, and a chaotic run of security releases since. The vendor has moved past 4.7.0; be on 4.7.2.

Another 23 Critical Security Vulnerabilities in Gridbox for Joomla

Another 23 Critical Security Vulnerabilities in Gridbox for Joomla

Balbooa asked mySites.guru to audit Gridbox for Joomla. We found 23 vulnerabilities, including a pre-auth RCE, some exploited already. Fixed in 2.20.2.

PageBuilder CK RCE fixed - again - correctly this time

PageBuilder CK RCE fixed - again - correctly this time

PageBuilder CK's 3.6.0 fix for its file-upload RCE (CVE-2026-56290) added just a login check; any Editor could still run code. Fixed in 3.6.3. Be on 3.6.5.

PageBuilder CK File Upload RCE - June 2026

PageBuilder CK File Upload RCE - June 2026

PageBuilder CK below 3.6.0 lets anyone upload and run a file on your Joomla site, no login. CVE-2026-56290, CVSS 10.0, exploited in the wild. Update to 3.6.0.

Zero Day Vulnerability Found in iCagenda Joomla Extension

Zero Day Vulnerability Found in iCagenda Joomla Extension

mySites.guru found and confirmed an unauthenticated upload giving remote code execution on Joomla 6 sites running iCagenda. Fixed same-day in 4.0.8.

SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins

SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins

An unauthenticated upload in the SP Page Builder Joomla extension gives remote code execution and creates hidden Super User accounts. Fixed in 6.6.2.

Browse every article