Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index

Vulnerability

68 articles tagged Vulnerability, newest first.

Regular Labs Publishes 24 Joomla Extension Updates Including 10 Security Fixes

Regular Labs Publishes 24 Joomla Extension Updates Including 10 Security Fixes

Regular Labs shipped 24 Joomla extension updates on 13 September 2026. Ten fix security issues across nine CVEs, and four change behaviour on update.

Unauthenticated SQL Injection in SP Property Finder found by mySites.guru

Unauthenticated SQL Injection in SP Property Finder found by mySites.guru

mySites.guru found an unauthenticated blind SQL injection in JoomShaper's SP Property Finder. Any visitor could read the database. Fixed in 4.1.4.

Digital Peak patches four Joomla extensions after a Claude audit

Digital Peak patches four Joomla extensions after a Claude audit

Digital Peak shipped out-of-band fixes for DPCalendar, DPMedia, DPAttachments and DPCases on 10 September. DPAttachments is the one to do first.

T4 Page Builder 2.3.0 Fixes an Unauthenticated Mail Relay

T4 Page Builder 2.3.0 Fixes an Unauthenticated Mail Relay

JoomlArt's T4 Page Builder 2.3.0 closes an unauthenticated open mail relay we reported in August. A week on, five in six installs we see are still older.

J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws we reported

J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws we reported

J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws mySites.guru reported, including anonymous PayPal order confirmation and a 9.5 backend escalation.

DPCalendar 10.12.0 fixes an SQL injection and an XSS

DPCalendar 10.12.0 fixes an SQL injection and an XSS

Digital Peak fixed a blind SQL injection and a stored XSS in DPCalendar 10.12.0, backported to 8.19.5 for Joomla 3. Both need a logged-in user.

Helix Ultimate 2.2.10 Fixes Twelve Security Issues, Including a Pre-Login Bypass

Helix Ultimate 2.2.10 Fixes Twelve Security Issues, Including a Pre-Login Bypass

Helix Ultimate 2.2.10 is a security release for the Joomla template framework. Every version below it is affected. Here is what it fixes and how to update.

Helix Ultimate's Third Joomla 3 Patch Since JoomShaper Said There Would Be None

Helix Ultimate's Third Joomla 3 Patch Since JoomShaper Said There Would Be None

JoomShaper said its Joomla 3 products would get no security patches regardless of severity. The Helix Ultimate template framework has now had four.

Three CVEs in miniOrange Extensions for Joomla, All Now Fixed

Three CVEs in miniOrange Extensions for Joomla, All Now Fixed

Two CVSS 10.0 authentication bypasses and a remote uninstall flaw naming 23 extensions. Every affected free edition now has a fixed version, released 31 August.

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

Fabrik 4.7.2 for the Joomla extension closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Update now.

Five Security Issues in JEM (Joomla Event Manager), and No Stable Fix Yet

Five Security Issues in JEM (Joomla Event Manager), and No Stable Fix Yet

mySites.guru found and reported multiple security issues in JEM (Joomla Event Manager), including an unauthenticated article overwrite. No stable fix yet.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66

YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.

iCagenda 4.0.12 fixes an unauthenticated SQL injection

iCagenda 4.0.12 fixes an unauthenticated SQL injection

CVE-2026-67365 is an unauthenticated SQL injection in the iCagenda Calendar module for Joomla, scored 9.2 Critical. Fixed in 4.0.12.

Sourcerer 14 and 15 did not fix CVE-2026-74253. 16.0.0 does.

Sourcerer 14 and 15 did not fix CVE-2026-74253. 16.0.0 does.

Sourcerer 14 and 15 were both published as the fix for CVE-2026-74253 and neither closed it. It is exploited in the wild. Update now to 16.0.0.

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 on 6.x isn't offered it.

Unauthenticated Remote Code Execution in SP Page Builder found by mySites.guru

Unauthenticated Remote Code Execution in SP Page Builder found by mySites.guru

mySites.guru found a pre-authentication remote code execution flaw in SP Page Builder for Joomla, in the same release that fixed our earlier reports.

Cotton Cloud Patched the Login, Then the Data

Cotton Cloud Patched the Login, Then the Data

Two access control flaws in Cotton Cloud for Joomla. The first fix closed the door, not the room. CVE-2026-67283 and CVE-2026-67284 are fixed in 2.0.3.

The Fabrik Fiasco: Announced, Restricted, Relabelled

The Fabrik Fiasco: Announced, Restricted, Relabelled

Two CVSS 10.0 RCEs in the Fabrik Joomla extension, and a chaotic run of security releases since. The vendor has moved past 4.7.0; be on 4.7.2.

Another 23 Critical Security Vulnerabilities in Gridbox for Joomla

Another 23 Critical Security Vulnerabilities in Gridbox for Joomla

Balbooa asked mySites.guru to audit Gridbox for Joomla. We found 23 vulnerabilities, including a pre-auth RCE, some exploited already. Fixed in 2.20.2.

JCE 2.9.99.10 Fixes Another Security Issue

JCE 2.9.99.10 Fixes Another Security Issue

JCE 2.9.99.10 patches a file rename flaw letting a privileged user create a hidden file in the folder they were browsing. The release hardens more too.

Pre-Authentication SQL Injection and Mail Relay in SP Page Builder found by mySites.guru

Pre-Authentication SQL Injection and Mail Relay in SP Page Builder found by mySites.guru

mySites.guru found four vulnerabilities in SP Page Builder for Joomla: a SQL injection and a mail relay, fixed in 6.7.1. A fifth survived to 6.8.0.

Exposed Customer Invoices, Order Forgery and SQL Injection in EasyStore for Joomla found by mySites.guru

Exposed Customer Invoices, Order Forgery and SQL Injection in EasyStore for Joomla found by mySites.guru

Before EasyStore 2.0.2, any logged-in customer could read every other customer's invoice by editing one URL. mySites.guru found this and two more flaws.

Regular Labs Patched Its Whole Joomla Extension Catalogue at Once

Regular Labs Patched Its Whole Joomla Extension Catalogue at Once

Regular Labs shipped a security-hardening update across its Joomla extension range on 22 July 2026: SSRF, command injection, stored XSS and more. No CVEs.

PageBuilder CK RCE fixed - again - correctly this time

PageBuilder CK RCE fixed - again - correctly this time

PageBuilder CK's 3.6.0 fix for its file-upload RCE (CVE-2026-56290) added just a login check; any Editor could still run code. Fixed in 3.6.3. Be on 3.6.5.

Events Booking for Joomla exposes personal and financial data from invoices

Events Booking for Joomla exposes personal and financial data from invoices

An unauthenticated flaw in Events Booking for Joomla let anyone download any registrant's invoice, with their name, address, email and payment. Fixed in 5.8.2.

One VEL for Every Joomla and WordPress Site

One VEL for Every Joomla and WordPress Site

The Joomla VEL (Vulnerable Extension List) only covers Joomla and never checks your sites. mySites.guru tracks both CMSes and flags yours directly.

Your .htaccess Won't Stop a Joomla Hack

Your .htaccess Won't Stop a Joomla Hack

A hardened .htaccess feels safe, but Joomla attacks ride straight through index.php. Here is why the file protects far less than most site owners think.

Membership Pro 4.6.2: A Quiet Fix for Anonymous File Uploads

Membership Pro 4.6.2: A Quiet Fix for Anonymous File Uploads

Membership Pro 4.6.2 quietly fixes the same anonymous upload flaw we reported in Events Booking. Now CVE-2026-62415, rated critical. What to do about it.

Gridbox for Joomla: One Cookie and You Are a Super User

Gridbox for Joomla: One Cookie and You Are a Super User

A critical unauthenticated authentication bypass in Gridbox for Joomla let anyone become a Super User by setting a single cookie. Fixed in 2.20.1. Update now.

Events Booking for Joomla: Anyone Could Upload Files to Your Server

Events Booking for Joomla: Anyone Could Upload Files to Your Server

mySites.guru found two unauthenticated flaws in Events Booking for Joomla: file upload enabled by default, and a leak of every user's name and email.

DJ-Classifieds Unauthenticated File Upload

DJ-Classifieds Unauthenticated File Upload

DJ-Classifieds below 3.11.2 let anyone upload files to your Joomla site with no login, and it was being used in the wild. Update to 3.11.2 now.

jDownloads 4.1 Shipped an Unauthenticated Upload Endpoint, Now Fixed in 4.1.6

jDownloads 4.1 Shipped an Unauthenticated Upload Endpoint, Now Fixed in 4.1.6

jDownloads 4.1.0 to 4.1.5 shipped a leftover test script that let anyone upload files to your Joomla site with no login. Update to 4.1.6, which removes it.

We Are Not the Only Ones Auditing Joomla Extensions

We Are Not the Only Ones Auditing Joomla Extensions

Two Joomla extension flaws went public via the Joomla CNA: a SQL injection in JoomCCK and a stored XSS in ChronoForms. Neither was ours. Update now.

Unauthenticated SQL Injection in Quix Page Builder found by mySites.guru

Unauthenticated SQL Injection in Quix Page Builder found by mySites.guru

mySites.guru found and reported CVE-2026-58078, an unauthenticated SQL injection in Quix Page Builder for Joomla. Fixed in 6.2.1; update to 6.2.2.

JoomShaper Patched the Joomla 3 It Said It Never Would

JoomShaper Patched the Joomla 3 It Said It Never Would

Six days after ruling out Joomla 3 security patches, JoomShaper shipped them for Helix Ultimate, Helix3 and SP Page Builder. What is in them.

Unauthenticated SQL Injection in EDocman found by mySites.guru

Unauthenticated SQL Injection in EDocman found by mySites.guru

mySites.guru found an unauthenticated SQL injection in EDocman for Joomla that let anyone read the whole database. Fixed in 3.9.0 - update now.

The One-Click Way to Patch JoomShaper Extensions on Joomla 3

The One-Click Way to Patch JoomShaper Extensions on Joomla 3

mySites.guru backports JoomShaper's security fixes into SP Page Builder, Helix3 and Helix Ultimate on Joomla 3, across every site in your account.

Nineteen and Counting: Joomla Extension Vulnerabilities We Found and Disclosed in a Month

Nineteen and Counting: Joomla Extension Vulnerabilities We Found and Disclosed in a Month

In just over a month mySites.guru found and responsibly disclosed nineteen security issues in popular Joomla extensions, most of them critical.

Unauthenticated SQL Injection in DPCalendar found by mySites.guru

Unauthenticated SQL Injection in DPCalendar found by mySites.guru

mySites.guru found and reported an unauthenticated SQL injection in the DPCalendar Joomla extension's public events feed. Fixed in 10.11.2 and 8.19.4.

Phoca Download 6.1.3 Fixes an Authenticated Upload RCE

Phoca Download 6.1.3 Fixes an Authenticated Upload RCE

Phoca Download for Joomla (com_phocadownload) up to 6.1.2 let a logged-in member upload a PHP file and run code on the server. Fixed in 6.1.3, update now.

RSFiles! Fixes an Unauthenticated File Upload RCE

RSFiles! Fixes an Unauthenticated File Upload RCE

RSFiles! for Joomla (com_rsfiles) up to 1.17.11 had an unauthenticated file upload flaw letting anyone drop a PHP file and run code. Update now.

Unauthenticated SQL Injection in AcyMailing found by mySites.guru

Unauthenticated SQL Injection in AcyMailing found by mySites.guru

mySites.guru found and reported CVE-2026-56292, an unauthenticated SQL injection in AcyMailing for Joomla and WordPress. Update to 10.11.1 now.

JoomShaper Ends Joomla 3 Security Fixes

JoomShaper Ends Joomla 3 Security Fixes

JoomShaper ended Joomla 3 support with no security fixes regardless of severity, then reversed the security half six days later and shipped patches.

Balbooa Forms Fixes an Unauthenticated File Upload RCE

Balbooa Forms Fixes an Unauthenticated File Upload RCE

Balbooa Forms (com_baforms) had an unauthenticated file upload RCE, CVE-2026-56291, fixed in 2.4.1. Three more security releases followed: update to 2.4.3.2.

The Helix3 Defacement Lives in Your Database, Not Your Files

The Helix3 Defacement Lives in Your Database, Not Your Files

The Hacked by AntonKill defacement hits Joomla sites via Helix3, hiding in the database where file scanners never look. Clean it in one click.

Helix Ultimate 2.2.7 Closes an Unauthenticated Menu Write

Helix Ultimate 2.2.7 Closes an Unauthenticated Menu Write

Helix Ultimate 2.2.7 fixes CSRF and permission gaps in com_ajax: an unauthenticated menu write leading to stored XSS, a file delete, and an open redirect.

Helix3 Shipped a Critical Fix as "Security Update"

Helix3 Shipped a Critical Fix as "Security Update"

Helix3 3.1.1 patches an unauthenticated file write and file delete in the Helix3 ajax plugin. JoomShaper announced it but told nobody what it fixes.

PageBuilder CK File Upload RCE - June 2026

PageBuilder CK File Upload RCE - June 2026

PageBuilder CK below 3.6.0 lets anyone upload and run a file on your Joomla site, no login. CVE-2026-56290, CVSS 10.0, exploited in the wild. Update to 3.6.0.

Avada Builder 3.15.4 Patches an Unauthenticated File Deletion Flaw (CVE-2026-8713)

Avada Builder 3.15.4 Patches an Unauthenticated File Deletion Flaw (CVE-2026-8713)

Avada Builder 3.15.4 fixes a critical unauthenticated file deletion flaw (CVE-2026-8713, CVSS 9.1) that can delete wp-config.php and take over the site.

Zero Day Vulnerability Found in iCagenda Joomla Extension

Zero Day Vulnerability Found in iCagenda Joomla Extension

mySites.guru found and confirmed an unauthenticated upload giving remote code execution on Joomla 6 sites running iCagenda. Fixed same-day in 4.0.8.

SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins

SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins

An unauthenticated upload in the SP Page Builder Joomla extension gives remote code execution and creates hidden Super User accounts. Fixed in 6.6.2.

A New mySites.guru Tool to Find, and Fix, the JCE Profiles Hack (June 2026)

A New mySites.guru Tool to Find, and Fix, the JCE Profiles Hack (June 2026)

mySites.guru now has a dedicated check that finds rogue JCE editor profiles and webshells across your Joomla sites, then lets you clean and patch them.

JCE Pro 2.9.99.6 Is a Hardening Release After a Full Audit of Joomla's Most-Installed Editor

JCE Pro 2.9.99.6 Is a Hardening Release After a Full Audit of Joomla's Most-Installed Editor

JCE Pro 2.9.99.6 follows a four-day security audit of the editor, narrowing entry points and hardening input validation. Recommended for every JCE site.

JCE Free/Pro 2.9.99.5 Patches an Unauthenticated File Upload in Joomla's Most-Installed Editor

JCE Free/Pro 2.9.99.5 Patches an Unauthenticated File Upload in Joomla's Most-Installed Editor

JCE Free and JCE Pro 2.9.99.5 patch an unauthenticated editor profile upload that could upload arbitrary files. Update every Joomla site running JCE.

JCE Free/Pro 2.9.99.4 Patches Two Authenticated Vulnerabilities in Joomla's Most Popular Editor

JCE Free/Pro 2.9.99.4 Patches Two Authenticated Vulnerabilities in Joomla's Most Popular Editor

JCE Free and JCE Pro 2.9.99.4 patch an Editor Profile authentication bypass and a directory traversal in filesystem search. Update JCE today.

Joomla 5.4.6 and 6.1.1 Patch TEN Security Issues

Joomla 5.4.6 and 6.1.1 Patch TEN Security Issues

Joomla 5.4.6 and 6.1.1 close ten security issues including an MFA bypass and a com_users privilege escalation. The patch order for 30+ sites.

Avada Builder Patches Two Security Issues in 3.15.3

Avada Builder Patches Two Security Issues in 3.15.3

Avada Builder 3.15.3 patches an unauthenticated SQL injection and a Subscriber-level file read across 1 million WordPress sites. Find affected sites.

Breeze, Cloudways Cache Plugin, Has a Remote Code Execution Bug

Breeze, Cloudways Cache Plugin, Has a Remote Code Execution Bug

Wordfence blocked 3,936 attacks in 24 hours against Breeze Cache below 2.4.5. CVE-2026-3844 is unauthenticated RCE on 400,000+ WordPress sites.

AcyMailing Vulnerability Also Affects Joomla Sites

AcyMailing Vulnerability Also Affects Joomla Sites

CVE-2026-3614 is listed as a WordPress bug. We diffed the 10.8.1 and 10.8.2 source and the same vulnerable code ships to Joomla sites too.

The WordPress Plugin You Trusted Was Sold to an Attacker

The WordPress Plugin You Trusted Was Sold to an Attacker

A buyer acquired 31 WordPress plugins, planted a backdoor in August 2025, and activated it in April 2026. Here is what happened and how to check your sites.

Smart Slider 3 Pro 3.5.1.35 Was a Malicious Release: Supply Chain Compromise

Smart Slider 3 Pro 3.5.1.35 Was a Malicious Release: Supply Chain Compromise

Smart Slider 3 Pro 3.5.1.35 was a malicious release pushed through the official update channel. RCE backdoor, hidden admin users. Update to 3.5.1.36.

Ninja Forms File Uploads CVE-2026-0740: The AJAX Pattern Strikes Again

Ninja Forms File Uploads CVE-2026-0740: The AJAX Pattern Strikes Again

CVE-2026-0740 is a CVSS 9.8 unauthenticated RCE in the Ninja Forms File Uploads AJAX handler, exploited with over 118,600 attempts blocked by Wordfence.

4 Major WordPress Plugins Patched Security Flaws in March 2026

4 Major WordPress Plugins Patched Security Flaws in March 2026

Elementor, Yoast SEO, WPForms, and Really Simple Security all shipped security patches in March 2026. What was fixed, and how to verify your sites.

AJAX Endpoints Are A Big CMS Security Blind Spot

AJAX Endpoints Are A Big CMS Security Blind Spot

Five AJAX and API vulnerabilities hit Joomla and WordPress in March 2026, all sharing one root cause. Here is what went wrong and how to protect your sites.

Novarain Framework Vulnerability: Check Your Joomla Sites for nrframework

Novarain Framework Vulnerability: Check Your Joomla Sites for nrframework

CVE-2026-21627 (CVSS 9.5) - Tassos/Novarain Framework for Joomla allows unauthenticated file inclusion, deletion, and SQL injection.

Smart Slider 3 Hack Allows Any File to Be Downloaded

Smart Slider 3 Hack Allows Any File to Be Downloaded

CVE-2026-3098 lets any subscriber download wp-config.php from 800,000 WordPress sites running Smart Slider 3. How to check and fix it.

Astroid Framework Vulnerability - What Happened and How to Check Your Joomla Site

Astroid Framework Vulnerability - What Happened and How to Check Your Joomla Site

CVE-2026-21628 (CVSS 10.0) - Astroid Framework for Joomla had a critical auth bypass letting attackers upload backdoors. What happened and what to do.

WordPress Plugin Vulnerability Alerting

WordPress Plugin Vulnerability Alerting

mySites.guru cross-references every WordPress plugin on your sites against Wordfence, CVE and custom threat databases, flagging vulnerable plugins instantly.

Browse every article