Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

Joomla Vulnerability Database

These are the 343 vulnerability rules mySites.guru checks every connected Joomla site against, covering 204 extensions and 418 CVE-numbered vulnerabilities. A good number of them exist because we found the flaw ourselves and reported it to the developer before publishing.

Rules current as of 3 October 2026. Subscribers see which of their own sites are affected, on the site's Manage page.

Why no WordPress CVE or vulnerability data?

WordPress is covered by the service too: mySites.guru integrates Wordfence's vulnerability feed in full, mirroring the data published on Wordfence's vulnerability pages, and every connected WordPress site is checked against it on each audit. To research a WordPress plugin or theme yourself, search Wordfence's database directly.

Subscribe by RSS

New rules as we start checking sites against them. One item per rule, so a CVE needing a rule per Joomla branch appears once for each.

https://mysites.guru/vulnerabilities/rss.xml

One item per CVE instead

This page is public. Acting on it across a portfolio is the mySites.guru subscription: each audit checks every connected Joomla and WordPress site against these rules, flags the ones running an affected version, and updates the extension in one click across all of them. One price, unlimited sites, 90,000+ sites protected in 14 years.

Extensions we track

Filter by severity, or search for the extension or CVE you're after. Browse every tracked CVE at the Joomla CVE index.

ExtensionRulesSeverityLatestCVEs
Page Builder CKcom_pagebuilderck10Critical, High, Medium2026-08-17CVE-2026-74254CVE-2026-77993CVE-2026-77994CVE-2026-63048CVE-2026-62414CVE-2026-56290
J2Store / J2Commercecom_j2store9Critical, High2026-09-15CVE-2026-78081CVE-2026-81567CVE-2026-81568CVE-2026-82189CVE-2026-82190CVE-2026-82191CVE-2026-77999CVE-2026-78000CVE-2026-78064CVE-2026-78065CVE-2026-78069CVE-2026-67358CVE-2026-67359CVE-2026-67360CVE-2026-67361CVE-2026-67362CVE-2026-74252CVE-2020-13996
Phoca Cartcom_phocacart7Critical, High, Medium2026-10-01CVE-2026-74251CVE-2026-76564CVE-2026-76565
miniOrange SAML SSOcom_miniorange_saml6Critical, High2026-08-31CVE-2026-78074CVE-2026-77998
Phoca Downloadcom_phocadownload6Critical, High, Medium2026-07-10CVE-2026-57828CVE-2026-76569
miniOrange OAuth Clientcom_miniorange_oauth4Critical, High2026-08-31CVE-2026-78074CVE-2026-77995
SP Page Buildercom_sppagebuilder4Critical, High2026-09-14CVE-2026-78375CVE-2026-79700CVE-2026-79701CVE-2026-81564CVE-2026-81565CVE-2026-81566CVE-2026-67285CVE-2026-67286CVE-2026-67287CVE-2026-65876CVE-2026-65766CVE-2026-65877CVE-2026-66494CVE-2026-65878CVE-2026-65879CVE-2026-48908
Articles Anywherearticlesanywhere3Critical, High2026-09-13CVE-2026-85195CVE-2026-85196CVE-2026-64793CVE-2026-64794CVE-2026-64795CVE-2026-64799CVE-2026-65755
Balbooa Formscom_baforms3Critical2026-09-29CVE-2026-102425CVE-2026-102424CVE-2026-101127CVE-2026-101112CVE-2026-101126CVE-2026-67364CVE-2026-67363CVE-2026-65880CVE-2026-56291CVE-2025-49485
Conditional Contentconditionalcontent3Critical, Medium2026-09-13CVE-2026-85192CVE-2026-85188CVE-2026-63280CVE-2026-63281CVE-2026-63683CVE-2026-64792
Events Bookingcom_eventbooking3Critical, Medium2026-07-20CVE-2026-63047CVE-2026-58149CVE-2026-60024CVE-2026-60025
Gridboxcom_gridbox3Critical, High2026-09-21CVE-2026-61425CVE-2026-65884CVE-2026-65885CVE-2026-65889CVE-2026-65890CVE-2026-66488CVE-2026-66489CVE-2026-66490CVE-2026-65886CVE-2026-65887CVE-2026-65888CVE-2026-65947
Helix Ultimateshaper_helixultimate3Critical, High2026-08-31CVE-2026-78075CVE-2026-78076CVE-2026-78077CVE-2026-78078CVE-2026-78079CVE-2026-57829CVE-2026-57830
Helix Ultimate Frameworkhelixultimate3Critical, High2026-08-31CVE-2026-78075CVE-2026-78076CVE-2026-78077CVE-2026-78078CVE-2026-78079CVE-2026-57829CVE-2026-57830
iCagendacom_icagenda3Critical2026-06-15CVE-2026-48939CVE-2026-67365CVE-2026-71571CVE-2026-67366CVE-2026-71570
J-BusinessDirectorycom_jbusinessdirectory3Critical2026-08-19CVE-2026-75949CVE-2026-75954CVE-2026-75956CVE-2026-75950CVE-2026-75951CVE-2026-75952CVE-2026-75953CVE-2026-75955CVE-2020-5182CVE-2019-25752
JCEcom_jce3Critical, High, Medium2026-07-29CVE-2026-65891CVE-2026-48907CVE-2015-7339
Modules Anywheremodulesanywhere3Critical, High2026-09-27CVE-2026-100750CVE-2026-65757CVE-2026-64793CVE-2026-64795
Sourcerersourcerer3Critical, Low2026-08-17CVE-2026-74253CVE-2025-22204CVE-2026-64796
ZOOcom_zoo3Critical, High, Medium2026-08-21CVE-2026-76611CVE-2026-76612CVE-2026-77028CVE-2026-77029CVE-2026-76610CVE-2026-74803CVE-2026-74804CVE-2026-75114
AcyMailingcom_acym2Critical2026-09-24CVE-2026-94132CVE-2026-94131CVE-2026-56292CVE-2023-39970CVE-2023-39971CVE-2023-39972CVE-2023-39973CVE-2023-39974
Astroid Frameworkastroid2Critical2026-03-05CVE-2026-21628
Book Librarycom_booklibrary2Critical, Medium2026-09-28CVE-2026-101111CVE-2026-101110
Easy Folder Listing Procom_easyfolderlistingpro2Critical2024-11-26CVE-2024-11145
Fabrikcom_fabrik2Critical, High2026-08-22CVE-2026-76571CVE-2026-76596CVE-2026-76597CVE-2026-76598CVE-2026-76600CVE-2026-76601CVE-2026-76602CVE-2026-76603CVE-2026-76604CVE-2026-76605CVE-2026-76606CVE-2026-76607CVE-2026-76608CVE-2026-76609CVE-2026-77027CVE-2026-77992CVE-2026-76599CVE-2020-37219CVE-2026-67282CVE-2026-66915
jDownloadscom_jdownloads2Critical, Medium2026-07-17CVE-2026-61900CVE-2025-55758CVE-2022-27909
JEventscom_jevents2Critical2025-01-01CVE-2025-49467CVE-2015-7340
K2com_k22Critical, Medium2026-06-25CVE-2026-48941CVE-2026-48942CVE-2026-48943CVE-2026-48944CVE-2026-48945CVE-2026-48946CVE-2026-48940
OS CCKcom_os_cck2Critical, High2026-09-30CVE-2026-102427
OS Gallerycom_osgallery2Critical2026-09-20CVE-2026-88854CVE-2026-88857CVE-2026-88856CVE-2026-88855
Real Estate Managercom_realestatemanager2Critical, Medium2026-09-28CVE-2026-100753CVE-2026-100752
Smart Slider 3 Prosmartslider32Critical, Medium2026-04-08CVE-2026-34424
UP Universal Pluginup2Critical2026-09-26CVE-2026-97160CVE-2026-97161CVE-2026-97162CVE-2026-97163
Vehicle Managercom_vehiclemanager2Critical, Medium2026-09-28CVE-2026-101109CVE-2026-101108
Aimy Captcha-Less Form Guardaimycaptchalessformguard1Critical2026-07-28CVE-2026-65883
Articles Calendarmod_articles_calendar1Critical2025-07-18CVE-2025-26855
Articles Calendararticlescalendar1Critical2025-07-18CVE-2025-26855
BrainCert Virtual Classroomcom_virtualclassroom1Critical2023-08-07CVE-2023-34477
Conditional Contentpkg_conditionalcontent1Critical2026-09-13CVE-2026-85192CVE-2026-85188
Creative Contact Formcom_creativecontactform1Critical2020-03-04CVE-2014-8739CVE-2020-9364
DJ-Classifiedscom_djclassifieds1Critical2026-07-20CVE-2026-61424CVE-2025-54474
EDocmancom_edocman1Critical2026-07-14CVE-2026-57832
Helix3 Templateshaper_helix31Critical2026-06-29CVE-2026-49049
JCTablescom_jctables1Critical2026-09-30CVE-2026-76570
JEM - Joomla Event Managercom_jem1Critical2026-08-27CVE-2026-77034CVE-2026-77035CVE-2026-77989CVE-2026-77990CVE-2026-77991
JooDatabasecom_joodb1Critical2026-09-03CVE-2026-78080
JoomCCKcom_joomcck1Critical2026-07-17CVE-2026-49048
LMS Litecom_lmslite1Critical2023-12-14CVE-2023-40629
Regular Labs GeoIPgeoip1Critical2026-07-23CVE-2026-65431CVE-2026-64876CVE-2026-65430CVE-2026-64875
RSFiles!com_rsfiles1Critical2026-07-10CVE-2026-57827CVE-2025-50057
RSForm!Procom_rsform1Critical2025-01-01CVE-2025-30085CVE-2025-27444
SP LMScom_splms1Critical2026-01-01CVE-2026-48909
SP Property Findercom_spproperty1Critical2026-09-10CVE-2026-78082CVE-2026-78303CVE-2026-78083CVE-2026-78084CVE-2026-78302CVE-2026-78085
Starshopcom_starshop1Critical2023-12-14CVE-2023-49708
Visitors Countermod_vvisit_counter1Critical2025-10-03CVE-2025-40636
YouTube Gallerycom_youtubegallery1Critical2026-09-26CVE-2026-94130
Snippetscom_snippets9High, Medium2026-09-13CVE-2026-88852CVE-2026-63684CVE-2026-64792CVE-2026-63265
DPCalendarcom_dpcalendar7High, Medium2026-08-28CVE-2026-78071CVE-2026-78070CVE-2026-57831CVE-2024-21727
YOOtheme Proyootheme6High, Medium2026-08-25CVE-2026-77997CVE-2026-76613CVE-2026-75115
Convert Formscom_convertforms5High2026-07-23CVE-2026-65758CVE-2024-40744CVE-2024-40745CVE-2025-22212CVE-2026-77026
Tabs & Accordionstabsaccordions5High, Medium2026-09-27CVE-2026-100751CVE-2026-85191CVE-2026-64792CVE-2026-63265
Visformscom_visforms4High-CVE-2023-23753
Modalsmodals3High2026-09-13CVE-2026-85189CVE-2026-88853CVE-2026-65713
Quix Page Buildercom_quix3High2026-07-15CVE-2026-58078CVE-2026-60026CVE-2026-60027CVE-2026-60028CVE-2026-60029CVE-2026-60030CVE-2026-60031
EasyStorecom_easystore2High2026-09-23CVE-2026-90899CVE-2026-90900CVE-2026-90901CVE-2026-90902CVE-2026-90903CVE-2026-90904CVE-2026-90905CVE-2026-65759CVE-2026-65760CVE-2026-65761
JoomGallerycom_joomgallery2High, Medium2026-09-15CVE-2026-84048CVE-2026-66917CVE-2026-66916
miniOrange LDAP Integrationcom_miniorange_dirsync2High2026-08-31CVE-2026-78074CVE-2023-23749
Phoca Commandercom_phocacommander2High2026-07-27CVE-2026-65764CVE-2026-65765CVE-2025-54473CVE-2026-66491CVE-2026-66492CVE-2026-66493
Quick Indexquickindex2High, Medium2026-09-13CVE-2026-85190CVE-2026-63265
Sexy Polling Reloadedcom_sexypolling2High2026-08-28CVE-2026-78072
Snippetspkg_snippets2High2026-09-13CVE-2026-88852
Tabs & Accordionspkg_tabsaccordions2High2026-09-27CVE-2026-100751CVE-2026-85191
Users Anywhereusersanywhere2High, Medium2026-09-13CVE-2026-85196CVE-2026-64794CVE-2026-64795CVE-2026-64799CVE-2026-65755
YOOtheme Prolocation2High2026-08-25CVE-2026-77996
4Analyticscom_foranalytics1High2026-07-15CVE-2026-58077CVE-2026-57833
AcyMailingcom_acymailing1High2020-03-09CVE-2015-7338
Admiror Framesadmirorframes1High2024-06-28CVE-2024-5735CVE-2024-5736CVE-2024-5737
Articles Anywherepkg_articlesanywhere1High2026-09-13CVE-2026-85195CVE-2026-85196
ChronoForms 8com_chronoforms81High2026-07-17CVE-2026-58148
DPAttachmentscom_dpattachments1High2026-09-10-
DPAttachmentspkg_dpattachments1High2026-09-10-
DPCasescom_dpcases1High2026-09-10-
DPCasespkg_dpcases1High2026-09-10-
DPMedialib_dpmedia1High2026-09-10-
DPMediapkg_dpmedia1High2026-09-10-
Easy Shopcom_easyshop1High2019-01-01CVE-2019-25760
EasyDiscusscom_easydiscuss1High2026-01-16CVE-2026-21623CVE-2026-21624CVE-2026-21625CVE-2026-21626
Event Gallerycom_eventgallery1High2026-09-26CVE-2026-97164CVE-2026-97165CVE-2026-100747CVE-2026-100748CVE-2026-100749
Event Registration Pro Calendarcom_registrationpro1High2017-01-01CVE-2017-20273
Extra Searchcom_extrasearch1High2017-01-01CVE-2017-20281
Flip Wallcom_flipwall1High2026-06-19CVE-2017-20265
Gurucom_guru1High-CVE-2022-23802
HDW Playercom_hdwplayer1High2026-05-13CVE-2020-37218
Ignite Gallerycom_igallery1High2026-07-07-
J-ClassifiedsManagercom_displayads1High2019-01-01CVE-2019-25751
J-MultipleHotelReservationcom_jmultiplehotelreservation1High2019-01-01CVE-2019-25750
jCartcom_jcart1High2017-01-01CVE-2017-20282
JHotelReservationcom_jhotelreservation1High2019-01-01CVE-2019-25748
jNewscom_jnews1High2020-03-09CVE-2015-7341CVE-2015-7342CVE-2015-7343
Jomrescom_jomres1High2026-05-23CVE-2013-3931CVE-2013-3932CVE-2018-25354
JoomCRMcom_joomcrm1High2019-01-01CVE-2019-25761
Joomdlecom_joomdle1High2026-07-28CVE-2026-65881CVE-2026-65882
LMS King Professionalcom_lmsking1High2017-01-01CVE-2017-20274
miniOrange Custom APIcom_miniorange_customapi1High2026-08-31CVE-2026-78074
miniOrange Import Export Userscom_miniorange_importexportusers1High2026-08-31CVE-2026-78074
miniOrange Keycloak User Synccom_miniorange_keycloaksync1High2026-08-31CVE-2026-78074
miniOrange Restrict Files / Folderscom_miniorange_mediarestriction1High2026-08-31CVE-2026-78074
miniOrange SCIM User Provisioningcom_miniorange_scim1High2026-08-31CVE-2026-78074
miniOrange Two Factor Authenticationcom_miniorange_twofa1High2026-08-31CVE-2026-78074
Modalspkg_modals1High2026-09-13CVE-2026-85189CVE-2026-88853
Modules Anywherepkg_modulesanywhere1High2026-09-27CVE-2026-100750
MyPortfoliocom_myportfolio1High2017-01-01CVE-2017-20280
OS Propertycom_osproperty1High2026-08-09-
paGO Commercecom_pago1High2020-09-18CVE-2020-25751
PHP-Bridgecom_phpbridge1High2017-01-01CVE-2017-20275
Quantum Managercom_quantummanager1High2025-08-25CVE-2025-54300CVE-2025-54301
Quick Indexpkg_quickindex1High2026-09-13CVE-2026-85190
Regular Labs DB Replacercom_dbreplacer1High2026-07-22CVE-2026-63685CVE-2026-63265
Regular Labs Extension Managercom_regularlabsmanager1High2026-07-22CVE-2026-64791CVE-2026-63265
Regular Labs IP Loginiplogin1High2026-07-22CVE-2026-64797CVE-2026-64798CVE-2026-63265
RO CSVIcom_csvi1High2026-07-28CVE-2026-65943CVE-2026-65944CVE-2026-65946
S5 Registermod_s5_register1High2023-12-14CVE-2023-49707
StreetGuessr Gamecom_streetguess1High2017-01-01CVE-2017-20271
Survey Force Deluxecom_surveyforce1High2026-06-19CVE-2017-20256
T4 Page Buildercom_t4pagebuilder1High2026-08-28CVE-2026-78374
Twitch TVcom_twitchtv1High2017-01-01CVE-2017-20270
Ultimate Property Listingcom_upl1High2017-01-01CVE-2017-20272
vAccountcom_vaccount1High2019-01-01CVE-2019-25756
vBizzcom_vbizz1High2019-01-01CVE-2019-25758CVE-2019-25759
VMapcom_vmap1High2019-01-01CVE-2019-25753
vReviewcom_vreview1High2019-01-01CVE-2019-25755
vWishlistcom_vwishlist1High2019-01-01CVE-2019-25757
Content Templatercom_contenttemplater5Medium2026-09-13CVE-2026-85188CVE-2026-63684CVE-2026-63280CVE-2026-63281CVE-2026-63683
Advanced Module Manageradvancedmodules4Medium2026-09-13CVE-2026-85188CVE-2026-63280CVE-2026-63281CVE-2026-63683CVE-2026-63265
ReReplacercom_rereplacer4Medium2026-09-13CVE-2026-85188CVE-2026-65754CVE-2026-63684CVE-2026-63280CVE-2026-63281
JoomShoppingcom_jshopping2Medium, Low2026-07-22CVE-2026-63264CVE-2025-22211
Phoca Mapscom_phocamaps2Medium2026-07-23CVE-2026-65763CVE-2026-23900
Advanced Module Managerpkg_advancedmodules1Medium2026-09-13CVE-2026-85188
All Video Sharecom_allvideoshare1Medium2026-08-28CVE-2026-78073
Balbooa Gallerycom_bagallery1Medium2025-07-18CVE-2025-49486CVE-2023-23757
Balbooa Gallerycom_gallery1Medium2026-08-18-
Booking - Book Itcom_booking1Medium2023-01-01CVE-2023-54357
CCommentcom_comment1Medium2025-07-23CVE-2025-54297
Clicky Analytics Dashboardmod_clicky_dash1Medium2023-12-14CVE-2023-40658
Content Templaterpkg_contenttemplater1Medium2026-09-13CVE-2026-85188
DJ-HelpfulArticlescom_djhelpfularticles1Medium2024-07-09CVE-2024-27183
Easy Quick Contactmod_easyquickcontact1Medium2023-12-14CVE-2023-40659
iProperty Real Estatecom_iproperty1Medium2026-04-09CVE-2023-54361
JLex Reviewcom_jlexreview1Medium2026-04-09CVE-2023-54360
JoomProjectcom_jpprojects1Medium2019-01-01CVE-2019-25762
JS Jobscom_jsjobs1Medium2026-06-04CVE-2019-25740CVE-2018-25327CVE-2025-22206CVE-2025-22208CVE-2025-22209CVE-2025-49484CVE-2025-54475
LivingWordcom_livingword1Medium2023-12-14CVE-2023-40627
Membership Procom_osmembership1Medium2026-07-21CVE-2026-62415
oneVotecom_onevote1Medium2023-07-11CVE-2023-23756
osTicky2com_osticky21Medium2024-02-15CVE-2024-21728
Phoca Guestbookcom_phocaguestbook1Medium2026-07-23CVE-2026-65762
Regular Labs Better Frontend Linkmod_betterfrontendlink1Medium2026-07-22CVE-2026-63265
Regular Labs CDNcdnforjoomla1Medium2026-07-22CVE-2026-65712CVE-2026-63265
Regular Labs Email Protectoremailprotector1Medium2026-07-22CVE-2026-63265
ReReplacerpkg_rereplacer1Medium2026-09-13CVE-2026-85188
RSBlog!com_rsblog1Medium2025-01-01CVE-2025-50126CVE-2025-27754
Solidrescom_solidres1Medium2026-04-09CVE-2023-54363
Users Anywherepkg_usersanywhere1Medium2026-09-13CVE-2026-85196
VirtueMartcom_virtuemart1Medium2026-04-09CVE-2023-54362CVE-2025-25228CVE-2025-55757
XCloner Backupcom_xcloner-backupandrestore1Medium2020-05-23CVE-2020-13424
HikaShopcom_hikashop1Low2026-07-20CVE-2026-61901CVE-2023-38044CVE-2024-40746CVE-2025-22210CVE-2025-25225CVE-2015-7344
SEBLODcom_cck3Unrated-CVE-2026-66914
Cache Cleanercachecleaner2Unrated-CVE-2026-64871CVE-2026-64872CVE-2026-64873CVE-2026-64874
Cotton Cloudcom_cotton2Unrated-CVE-2026-67283CVE-2026-67284
Admiror Gallerycom_admirorgallery1Unrated-CVE-2025-22205CVE-2023-38045
Ajax Quizcom_ajaxquiz1Unrated-CVE-2017-20262
Cache Cleanerpkg_cachecleaner1Unrated-CVE-2026-64871CVE-2026-64872CVE-2026-64873CVE-2026-64874
CommentBoxcom_commentbox1Unrated-CVE-2025-54298
Creative Gallerycom_creativegallery1Unrated-CVE-2023-23758
DJ-Flyercom_djflyer1Unrated-CVE-2025-50127
DJ-Reviewscom_djreviews1Unrated-CVE-2025-54295
DOCmancom_docman1Unrated-CVE-2022-27910
eXtplorercom_extplorer1Unrated-CVE-2023-40628
FocalPointcom_focalpoint1Unrated-CVE-2017-20263
iCagenda Calendar modulemod_icagenda_calendar1Unrated-CVE-2026-67365
JCDashboardscom_jcdashboards1Unrated-CVE-2023-40630
JMediacom_jmedia1Unrated-CVE-2026-60032CVE-2026-60033CVE-2026-60034
JoomDOCcom_joomdoc1Unrated-CVE-2023-40657
Joomla Quiz Deluxecom_joomlaquiz1Unrated-CVE-2017-20257
JoomRecipecom_joomrecipe1Unrated-CVE-2017-20277CVE-2017-20278
Keyboard Shortcutskeyboardshortcuts1Unrated-CVE-2026-65756
Komentocom_komento1Unrated-CVE-2025-54294
No Boss Calendarcom_nobosscalendar1Unrated-CVE-2025-49468
No Boss Testimonialscom_nobosstestimonials1Unrated-CVE-2025-54299
OSDownloadscom_osdownloads1Unrated-CVE-2017-20259
Payagecom_payage1Unrated-CVE-2017-20279
ProFilescom_profiles1Unrated-CVE-2025-54296
Proforms Basiccom_proforms1Unrated-CVE-2023-34476CVE-2023-40655
QuickFormcom_quickform1Unrated-CVE-2023-40656
RSDirectory!com_rsdirectory1Unrated-CVE-2025-50058
RSFirewall!com_rsfirewall1Unrated-CVE-2025-27445
RSMail!com_rsmail1Unrated-CVE-2025-50056CVE-2025-30084
RSMediaGallery!com_rsmediagallery1Unrated-CVE-2025-27753CVE-2025-32466
RSTickets! Procom_rsticketspro1Unrated-CVE-2025-32465
SIMGenealogycom_simgenealogy1Unrated-CVE-2017-20276
SP Movie Databasecom_spmoviedb1Unrated-CVE-2017-20266
Sponsor Wallcom_sponsorwall1Unrated-CVE-2017-20264
Tooltipstooltips1Unrated--
Zap Calendarcom_zcalendar1Unrated-CVE-2017-20268

Vulnerabilities we found and disclosed

90 write-ups. Every one was reported privately to the developer first.

14 More Joomla 3 Security Fixes, Each Tested on a Real 3.10.12 Site

14 More Joomla 3 Security Fixes, Each Tested on a Real 3.10.12 Site

Joomla 5.4.9 fixed 16 core issues. We backported every one reaching Joomla 3 to the mySites.guru one-click patch tool, each proved on a real 3.10.12 site.

SP Page Builder's Joomla 3 Security Patch Was Incomplete. Version 1.0.3 Fixes It.

SP Page Builder's Joomla 3 Security Patch Was Incomplete. Version 1.0.3 Fixes It.

JoomShaper's first Joomla 3 security patch for SP Page Builder left the captcha bypass live and the XSS fix incomplete. Version 1.0.3 closes both.

Phoca Cart 6.1.9 stops anyone downloading other customers' paid files

Phoca Cart 6.1.9 stops anyone downloading other customers' paid files

Phoca Cart before 6.1.9 let anonymous visitors download the digital products other customers bought. Only the Joomla 6 line is fixed, and 6.1.8 is affected.

Quix Page Builder 6.3.4 Fixes Guest Access and Editor Code Execution Flaws

Quix Page Builder 6.3.4 Fixes Guest Access and Editor Code Execution Flaws

Quix Page Builder 6.3.4 stops guests changing Quix settings or reading restricted pages, and editors running code on the server. Update every Joomla site.

AcyMailing Shoots Itself in the Foot With a Vanishing Update Site

AcyMailing Shoots Itself in the Foot With a Vanishing Update Site

AcyMailing adds its Joomla update site from PHP, not its manifest, so Rebuild deletes it and Joomla calls a site on a vulnerable version up to date.

OS CCK 8.3.16 for Joomla Fixes a No-Login PHP Upload and an SQL Injection, but the Updater Still Offers 8.3.14

OS CCK 8.3.16 for Joomla Fixes a No-Login PHP Upload and an SQL Injection, but the Updater Still Offers 8.3.14

OS CCK for Joomla before 8.3.16 let anyone upload and run PHP (CVE-2026-102427, CVSS 10.0) and had a no-login SQL injection. The updater won't offer the fix.

JCTables for Joomla: Unauthenticated SQL Injection Fixed in 1.21.1

JCTables for Joomla: Unauthenticated SQL Injection Fixed in 1.21.1

CVE-2026-76570 lets anyone read and rewrite a Joomla database through the JCTables extension without logging in. Scored 10.0 Critical, fixed in 1.21.1.

Joomla 5.4.9 and 6.1.4 Fix 16 Security Issues, Two Rated High

Joomla 5.4.9 and 6.1.4 Fix 16 Security Issues, Two Rated High

Joomla 5.4.9 and 6.1.4 fix 16 core security issues, including cache directory deletion, SSRF, an MFA bypass and account creation with registration switched off.

Balbooa Forms 2.4.3.4 Fixes Five Security Issues

Balbooa Forms 2.4.3.4 Fixes Five Security Issues

Balbooa Forms 2.4.3.4 fixes five CVEs in the Joomla form builder, led by a 9.5 unauthenticated RCE. Every version below 2.4.3.4 is affected. Update now.

Three OrdaSoft Joomla Extensions Have Unauthenticated SQL Injections in Their Sort Order

Three OrdaSoft Joomla Extensions Have Unauthenticated SQL Injections in Their Sort Order

Real Estate Manager, Vehicle Manager and Book Library for Joomla each have an SQL injection needing no login and a reflected XSS. Six CVEs and their fixes.

Modules Anywhere 10.0.0 and Tabs & Accordions 3.2.0 Close Two Content Author Security Holes

Modules Anywhere 10.0.0 and Tabs & Accordions 3.2.0 Close Two Content Author Security Holes

CVE-2026-100750 and CVE-2026-100751: Regular Labs fixed two High severity issues in Modules Anywhere 10.0.0 and Tabs & Accordions 3.2.0 for Joomla.

UP 6.1.0 fixes file read and code execution in the UP plugin for Joomla

UP 6.1.0 fixes file read and code execution in the UP plugin for Joomla

Before UP 6.1.0, one anonymous request could read a Joomla site's configuration.php through the UP plugin, and any author could run PHP. We found it.

Every disclosure we have published