Vulnerability
68 articles tagged Vulnerability, newest first.

Regular Labs Publishes 24 Joomla Extension Updates Including 10 Security Fixes
Regular Labs shipped 24 Joomla extension updates on 13 September 2026. Ten fix security issues across nine CVEs, and four change behaviour on update.

Unauthenticated SQL Injection in SP Property Finder found by mySites.guru
mySites.guru found an unauthenticated blind SQL injection in JoomShaper's SP Property Finder. Any visitor could read the database. Fixed in 4.1.4.

Digital Peak patches four Joomla extensions after a Claude audit
Digital Peak shipped out-of-band fixes for DPCalendar, DPMedia, DPAttachments and DPCases on 10 September. DPAttachments is the one to do first.

T4 Page Builder 2.3.0 Fixes an Unauthenticated Mail Relay
JoomlArt's T4 Page Builder 2.3.0 closes an unauthenticated open mail relay we reported in August. A week on, five in six installs we see are still older.

J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws we reported
J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws mySites.guru reported, including anonymous PayPal order confirmation and a 9.5 backend escalation.

DPCalendar 10.12.0 fixes an SQL injection and an XSS
Digital Peak fixed a blind SQL injection and a stored XSS in DPCalendar 10.12.0, backported to 8.19.5 for Joomla 3. Both need a logged-in user.

Helix Ultimate 2.2.10 Fixes Twelve Security Issues, Including a Pre-Login Bypass
Helix Ultimate 2.2.10 is a security release for the Joomla template framework. Every version below it is affected. Here is what it fixes and how to update.

Helix Ultimate's Third Joomla 3 Patch Since JoomShaper Said There Would Be None
JoomShaper said its Joomla 3 products would get no security patches regardless of severity. The Helix Ultimate template framework has now had four.

Three CVEs in miniOrange Extensions for Joomla, All Now Fixed
Two CVSS 10.0 authentication bypasses and a remote uninstall flaw naming 23 extensions. Every affected free edition now has a fixed version, released 31 August.

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes
Fabrik 4.7.2 for the Joomla extension closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Update now.

Five Security Issues in JEM (Joomla Event Manager), and No Stable Fix Yet
mySites.guru found and reported multiple security issues in JEM (Joomla Event Manager), including an unauthenticated article overwrite. No stable fix yet.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66
YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.

iCagenda 4.0.12 fixes an unauthenticated SQL injection
CVE-2026-67365 is an unauthenticated SQL injection in the iCagenda Calendar module for Joomla, scored 9.2 Critical. Fixed in 4.0.12.

Sourcerer 14 and 15 did not fix CVE-2026-74253. 16.0.0 does.
Sourcerer 14 and 15 were both published as the fix for CVE-2026-74253 and neither closed it. It is exploited in the wild. Update now to 16.0.0.

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection
Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 on 6.x isn't offered it.

Unauthenticated Remote Code Execution in SP Page Builder found by mySites.guru
mySites.guru found a pre-authentication remote code execution flaw in SP Page Builder for Joomla, in the same release that fixed our earlier reports.

Cotton Cloud Patched the Login, Then the Data
Two access control flaws in Cotton Cloud for Joomla. The first fix closed the door, not the room. CVE-2026-67283 and CVE-2026-67284 are fixed in 2.0.3.

The Fabrik Fiasco: Announced, Restricted, Relabelled
Two CVSS 10.0 RCEs in the Fabrik Joomla extension, and a chaotic run of security releases since. The vendor has moved past 4.7.0; be on 4.7.2.

Another 23 Critical Security Vulnerabilities in Gridbox for Joomla
Balbooa asked mySites.guru to audit Gridbox for Joomla. We found 23 vulnerabilities, including a pre-auth RCE, some exploited already. Fixed in 2.20.2.

JCE 2.9.99.10 Fixes Another Security Issue
JCE 2.9.99.10 patches a file rename flaw letting a privileged user create a hidden file in the folder they were browsing. The release hardens more too.

Pre-Authentication SQL Injection and Mail Relay in SP Page Builder found by mySites.guru
mySites.guru found four vulnerabilities in SP Page Builder for Joomla: a SQL injection and a mail relay, fixed in 6.7.1. A fifth survived to 6.8.0.

Exposed Customer Invoices, Order Forgery and SQL Injection in EasyStore for Joomla found by mySites.guru
Before EasyStore 2.0.2, any logged-in customer could read every other customer's invoice by editing one URL. mySites.guru found this and two more flaws.

Regular Labs Patched Its Whole Joomla Extension Catalogue at Once
Regular Labs shipped a security-hardening update across its Joomla extension range on 22 July 2026: SSRF, command injection, stored XSS and more. No CVEs.

PageBuilder CK RCE fixed - again - correctly this time
PageBuilder CK's 3.6.0 fix for its file-upload RCE (CVE-2026-56290) added just a login check; any Editor could still run code. Fixed in 3.6.3. Be on 3.6.5.

Events Booking for Joomla exposes personal and financial data from invoices
An unauthenticated flaw in Events Booking for Joomla let anyone download any registrant's invoice, with their name, address, email and payment. Fixed in 5.8.2.

One VEL for Every Joomla and WordPress Site
The Joomla VEL (Vulnerable Extension List) only covers Joomla and never checks your sites. mySites.guru tracks both CMSes and flags yours directly.

Your .htaccess Won't Stop a Joomla Hack
A hardened .htaccess feels safe, but Joomla attacks ride straight through index.php. Here is why the file protects far less than most site owners think.

Membership Pro 4.6.2: A Quiet Fix for Anonymous File Uploads
Membership Pro 4.6.2 quietly fixes the same anonymous upload flaw we reported in Events Booking. Now CVE-2026-62415, rated critical. What to do about it.

Gridbox for Joomla: One Cookie and You Are a Super User
A critical unauthenticated authentication bypass in Gridbox for Joomla let anyone become a Super User by setting a single cookie. Fixed in 2.20.1. Update now.

Events Booking for Joomla: Anyone Could Upload Files to Your Server
mySites.guru found two unauthenticated flaws in Events Booking for Joomla: file upload enabled by default, and a leak of every user's name and email.

DJ-Classifieds Unauthenticated File Upload
DJ-Classifieds below 3.11.2 let anyone upload files to your Joomla site with no login, and it was being used in the wild. Update to 3.11.2 now.

jDownloads 4.1 Shipped an Unauthenticated Upload Endpoint, Now Fixed in 4.1.6
jDownloads 4.1.0 to 4.1.5 shipped a leftover test script that let anyone upload files to your Joomla site with no login. Update to 4.1.6, which removes it.

We Are Not the Only Ones Auditing Joomla Extensions
Two Joomla extension flaws went public via the Joomla CNA: a SQL injection in JoomCCK and a stored XSS in ChronoForms. Neither was ours. Update now.

Unauthenticated SQL Injection in Quix Page Builder found by mySites.guru
mySites.guru found and reported CVE-2026-58078, an unauthenticated SQL injection in Quix Page Builder for Joomla. Fixed in 6.2.1; update to 6.2.2.

JoomShaper Patched the Joomla 3 It Said It Never Would
Six days after ruling out Joomla 3 security patches, JoomShaper shipped them for Helix Ultimate, Helix3 and SP Page Builder. What is in them.

Unauthenticated SQL Injection in EDocman found by mySites.guru
mySites.guru found an unauthenticated SQL injection in EDocman for Joomla that let anyone read the whole database. Fixed in 3.9.0 - update now.

The One-Click Way to Patch JoomShaper Extensions on Joomla 3
mySites.guru backports JoomShaper's security fixes into SP Page Builder, Helix3 and Helix Ultimate on Joomla 3, across every site in your account.

Nineteen and Counting: Joomla Extension Vulnerabilities We Found and Disclosed in a Month
In just over a month mySites.guru found and responsibly disclosed nineteen security issues in popular Joomla extensions, most of them critical.

Unauthenticated SQL Injection in DPCalendar found by mySites.guru
mySites.guru found and reported an unauthenticated SQL injection in the DPCalendar Joomla extension's public events feed. Fixed in 10.11.2 and 8.19.4.

Phoca Download 6.1.3 Fixes an Authenticated Upload RCE
Phoca Download for Joomla (com_phocadownload) up to 6.1.2 let a logged-in member upload a PHP file and run code on the server. Fixed in 6.1.3, update now.

RSFiles! Fixes an Unauthenticated File Upload RCE
RSFiles! for Joomla (com_rsfiles) up to 1.17.11 had an unauthenticated file upload flaw letting anyone drop a PHP file and run code. Update now.

Unauthenticated SQL Injection in AcyMailing found by mySites.guru
mySites.guru found and reported CVE-2026-56292, an unauthenticated SQL injection in AcyMailing for Joomla and WordPress. Update to 10.11.1 now.

JoomShaper Ends Joomla 3 Security Fixes
JoomShaper ended Joomla 3 support with no security fixes regardless of severity, then reversed the security half six days later and shipped patches.

Balbooa Forms Fixes an Unauthenticated File Upload RCE
Balbooa Forms (com_baforms) had an unauthenticated file upload RCE, CVE-2026-56291, fixed in 2.4.1. Three more security releases followed: update to 2.4.3.2.

The Helix3 Defacement Lives in Your Database, Not Your Files
The Hacked by AntonKill defacement hits Joomla sites via Helix3, hiding in the database where file scanners never look. Clean it in one click.

Helix Ultimate 2.2.7 Closes an Unauthenticated Menu Write
Helix Ultimate 2.2.7 fixes CSRF and permission gaps in com_ajax: an unauthenticated menu write leading to stored XSS, a file delete, and an open redirect.

Helix3 Shipped a Critical Fix as "Security Update"
Helix3 3.1.1 patches an unauthenticated file write and file delete in the Helix3 ajax plugin. JoomShaper announced it but told nobody what it fixes.

PageBuilder CK File Upload RCE - June 2026
PageBuilder CK below 3.6.0 lets anyone upload and run a file on your Joomla site, no login. CVE-2026-56290, CVSS 10.0, exploited in the wild. Update to 3.6.0.

Avada Builder 3.15.4 Patches an Unauthenticated File Deletion Flaw (CVE-2026-8713)
Avada Builder 3.15.4 fixes a critical unauthenticated file deletion flaw (CVE-2026-8713, CVSS 9.1) that can delete wp-config.php and take over the site.

Zero Day Vulnerability Found in iCagenda Joomla Extension
mySites.guru found and confirmed an unauthenticated upload giving remote code execution on Joomla 6 sites running iCagenda. Fixed same-day in 4.0.8.
SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins
An unauthenticated upload in the SP Page Builder Joomla extension gives remote code execution and creates hidden Super User accounts. Fixed in 6.6.2.

A New mySites.guru Tool to Find, and Fix, the JCE Profiles Hack (June 2026)
mySites.guru now has a dedicated check that finds rogue JCE editor profiles and webshells across your Joomla sites, then lets you clean and patch them.

JCE Pro 2.9.99.6 Is a Hardening Release After a Full Audit of Joomla's Most-Installed Editor
JCE Pro 2.9.99.6 follows a four-day security audit of the editor, narrowing entry points and hardening input validation. Recommended for every JCE site.

JCE Free/Pro 2.9.99.5 Patches an Unauthenticated File Upload in Joomla's Most-Installed Editor
JCE Free and JCE Pro 2.9.99.5 patch an unauthenticated editor profile upload that could upload arbitrary files. Update every Joomla site running JCE.

JCE Free/Pro 2.9.99.4 Patches Two Authenticated Vulnerabilities in Joomla's Most Popular Editor
JCE Free and JCE Pro 2.9.99.4 patch an Editor Profile authentication bypass and a directory traversal in filesystem search. Update JCE today.

Joomla 5.4.6 and 6.1.1 Patch TEN Security Issues
Joomla 5.4.6 and 6.1.1 close ten security issues including an MFA bypass and a com_users privilege escalation. The patch order for 30+ sites.

Avada Builder Patches Two Security Issues in 3.15.3
Avada Builder 3.15.3 patches an unauthenticated SQL injection and a Subscriber-level file read across 1 million WordPress sites. Find affected sites.

Breeze, Cloudways Cache Plugin, Has a Remote Code Execution Bug
Wordfence blocked 3,936 attacks in 24 hours against Breeze Cache below 2.4.5. CVE-2026-3844 is unauthenticated RCE on 400,000+ WordPress sites.

AcyMailing Vulnerability Also Affects Joomla Sites
CVE-2026-3614 is listed as a WordPress bug. We diffed the 10.8.1 and 10.8.2 source and the same vulnerable code ships to Joomla sites too.

The WordPress Plugin You Trusted Was Sold to an Attacker
A buyer acquired 31 WordPress plugins, planted a backdoor in August 2025, and activated it in April 2026. Here is what happened and how to check your sites.

Smart Slider 3 Pro 3.5.1.35 Was a Malicious Release: Supply Chain Compromise
Smart Slider 3 Pro 3.5.1.35 was a malicious release pushed through the official update channel. RCE backdoor, hidden admin users. Update to 3.5.1.36.

Ninja Forms File Uploads CVE-2026-0740: The AJAX Pattern Strikes Again
CVE-2026-0740 is a CVSS 9.8 unauthenticated RCE in the Ninja Forms File Uploads AJAX handler, exploited with over 118,600 attempts blocked by Wordfence.

4 Major WordPress Plugins Patched Security Flaws in March 2026
Elementor, Yoast SEO, WPForms, and Really Simple Security all shipped security patches in March 2026. What was fixed, and how to verify your sites.

AJAX Endpoints Are A Big CMS Security Blind Spot
Five AJAX and API vulnerabilities hit Joomla and WordPress in March 2026, all sharing one root cause. Here is what went wrong and how to protect your sites.

Novarain Framework Vulnerability: Check Your Joomla Sites for nrframework
CVE-2026-21627 (CVSS 9.5) - Tassos/Novarain Framework for Joomla allows unauthenticated file inclusion, deletion, and SQL injection.

Smart Slider 3 Hack Allows Any File to Be Downloaded
CVE-2026-3098 lets any subscriber download wp-config.php from 800,000 WordPress sites running Smart Slider 3. How to check and fix it.

Astroid Framework Vulnerability - What Happened and How to Check Your Joomla Site
CVE-2026-21628 (CVSS 10.0) - Astroid Framework for Joomla had a critical auth bypass letting attackers upload backdoors. What happened and what to do.

WordPress Plugin Vulnerability Alerting
mySites.guru cross-references every WordPress plugin on your sites against Wordfence, CVE and custom threat databases, flagging vulnerable plugins instantly.