mySites.guru
|
| |
|
|
A CVSS 10.0 in Fabrik, and 23 more we found in Gridbox
Fabrik 4.6.7 shipped on 9 August as a security release, and the next morning the Joomla CNA published CVE-2026-66915: unauthenticated remote code execution through the calc element's AJAX endpoint, scored CVSS 10.0. Versions 1.0.0 through 4.6.6 are affected, which is every release the project has ever made. What turns this from an afternoon's update run into something more awkward is that 4.6.7 installs on Joomla 4.2 to 5.x only and needs a live subscription, so a site on Joomla 3 or Joomla 6 has no patched release to move to at all.
Balbooa asked us to audit Gridbox, their Joomla page builder, and we came back with 23 vulnerabilities. While we were still working through the fixes, the Joomla security team told us three of the routes were being exploited in the wild. It took three builds over two days to close everything, and the complete fix is Gridbox 2.20.2.
The other five have been sitting on the blog without a mailing. EDocman, DJ-Classifieds and jDownloads are three separate Joomla extensions that could be reached with no login at all, Avada Builder is the WordPress equivalent, and JCE 2.9.99.10 is the one that genuinely is routine. All four of the serious ones are the same shape as Fabrik: a public endpoint nobody thought of as public, sitting beside a well-guarded main path and never inheriting its checks.
Applying the update is the easy half of all of these. Working out which of your sites are on an affected version is the half that eats an afternoon, and it is what mySites.guru is for: every extension on every connected site in one list, with the vulnerable versions already flagged.
All posts are free to read on the blog
|
|
|
|
CVSS 10.0
Fabrik – anonymous code execution through the calc element
The calc element's whole job is to evaluate a PHP expression that the site builder wrote. That is the point of the element, and it is why people build with it. Switch on the option to recalculate over AJAX and that evaluation gains a second route through a front-end endpoint in com_fabrik, and that route could be reached by anyone: no login, no privileges, no user interaction. Joomla's input filter does run over the submitted data, but it is there to strip HTML for cross-site scripting purposes and leaves PHP syntax entirely alone. Credit where it is due: this was a clearly labelled, clearly dated security release carrying an instruction to update, published in two places on the day it shipped. We have written up plenty of vendors who buried a fix of this size under "improved input validation" and hoped nobody compared the packages.
|
|
|
|
Exploited in the wild
Gridbox – 23 vulnerabilities, and three were already being used
Among the 23 is a pre-authentication remote code execution reachable in a single request, and a registration flaw that let anyone put themselves into a privileged group. The Joomla CNA has published two of the CVEs so far and reserved nine more. A fix existing and a fix working turned out to be two different things. Balbooa's first build left four findings live, including an anonymous SQL injection we proved still dumped password hashes, and it took a third build on the same day to close the last two. Gridbox 2.20.2 is the one with all of it. Three routes were being exploited before that fix was complete, so a site that sat on 2.20.1 or earlier through that window needs checking, not just updating.
|
|
|
|
Routine update
JCE 2.9.99.10 – a small fix, and worth saying so plainly
One changelog item marked SECURITY. A logged-in user with an editor profile that grants file browser access, plus the Rename permission on top, could rename a file so that it vanished from the folder listing. Three conditions have to hold and the payoff is concealment rather than execution, so no CVE was assigned, and dressing that up as an emergency would only make it harder to be believed the next time something genuinely is one. We unpacked both releases and compared them file by file anyway. 2.9.99.10 hardens considerably more than the changelog admits, adding twenty extensions to the blocked executable list alone. Update at your usual cadence. The JCE release to chase is 2.9.99.5, because anything below it still carries June's unauthenticated flaw, now in CISA's Known Exploited Vulnerabilities catalog.
|
|
|
Four more, every one of them reachable with no login
|
|
|
|
|
|
|
|
Need help with your site?
Phil Taylor – Fixing websites since 2004
|
Found something wrong with your Joomla or WordPress site? If it were simple, you'd have fixed it already. I offer same-day expert help at a flat rate of £120 per incident. No hourly billing surprises.
✓ Hacked or compromised sites
✓ PHP errors and white screens
✓ Upgrades and PHP 8 compatibility
✓ Performance and hosting issues
|
If I can't add value, you don't pay
|
|
|
|