Skip to main content
mySites.guru
5+ live

Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE

Joomla extension vulnerabilities

These are the 215 vulnerability rules mySites.guru checks every connected Joomla site against, covering 162 extensions. A good number of them exist because we found the flaw ourselves and reported it to the developer before publishing.

Rules current as of 24 August 2026. Subscribers see which of their own sites are affected, on the site's Manage page.

Extensions we track

Filter by severity, or search for the extension you run.

ExtensionRulesSeverityLatest
Page Builder CKcom_pagebuilderck8Critical, High, Medium2026-08-17
Phoca Cartcom_phocacart6Critical, Medium-
Events Bookingcom_eventbooking3Critical, Medium2026-07-20
iCagendacom_icagenda3Critical2026-06-15
J-BusinessDirectorycom_jbusinessdirectory3Critical2026-08-19
JCEcom_jce3Critical, High, Medium2026-07-29
Phoca Downloadcom_phocadownload3Critical, High, Medium2026-07-10
SP Page Buildercom_sppagebuilder3Critical2026-07-27
Balbooa Formscom_baforms2Critical2026-08-18
Easy Folder Listing Procom_easyfolderlistingpro2Critical2024-11-26
Gridboxcom_gridbox2Critical2026-08-10
Helix Ultimateshaper_helixultimate2Critical2026-07-07
Helix Ultimate Frameworkhelixultimate2Critical2026-07-07
jDownloadscom_jdownloads2Critical, Medium2026-07-17
JEventscom_jevents2Critical2025-01-01
Smart Slider 3 Prosmartslider32Critical, Medium2026-04-08
Sourcerersourcerer2Critical2026-08-17
AcyMailingcom_acym1Critical2026-07-09
Aimy Captcha-Less Form Guardaimycaptchalessformguard1Critical2026-07-28
Articles Calendarmod_articles_calendar1Critical2025-07-18
Articles Calendararticlescalendar1Critical2025-07-18
Astroid Frameworkastroid1Critical2026-03-05
BrainCert Virtual Classroomcom_virtualclassroom1Critical2023-08-07
Creative Contact Formcom_creativecontactform1Critical2020-03-04
DJ-Classifiedscom_djclassifieds1Critical2026-07-20
EDocmancom_edocman1Critical2026-07-14
Helix3 Templateshaper_helix31Critical2026-06-29
JoomCCKcom_joomcck1Critical2026-07-17
K2com_k21Critical2026-01-01
LMS Litecom_lmslite1Critical2023-12-14
RSFiles!com_rsfiles1Critical2026-07-10
RSForm!Procom_rsform1Critical2025-01-01
SP LMScom_splms1Critical2026-01-01
Starshopcom_starshop1Critical2023-12-14
Visitors Countermod_vvisit_counter1Critical2025-10-03
Convert Formscom_convertforms5High2026-07-23
Visformscom_visforms4High-
DPCalendarcom_dpcalendar3High, Medium2026-07-13
Phoca Commandercom_phocacommander2High2026-07-27
4Analyticscom_foranalytics1High2026-07-15
AcyMailingcom_acymailing1High2020-03-09
Admiror Framesadmirorframes1High2024-06-28
ChronoForms 8com_chronoforms81High2026-07-17
Easy Shopcom_easyshop1High2019-01-01
EasyDiscusscom_easydiscuss1High2026-01-16
EasyStorecom_easystore1High-
Event Registration Pro Calendarcom_registrationpro1High2017-01-01
Extra Searchcom_extrasearch1High2017-01-01
Flip Wallcom_flipwall1High2026-06-19
HDW Playercom_hdwplayer1High2026-05-13
Ignite Gallerycom_igallery1High2026-07-07
J-ClassifiedsManagercom_displayads1High2019-01-01
J-MultipleHotelReservationcom_jmultiplehotelreservation1High2019-01-01
jCartcom_jcart1High2017-01-01
JHotelReservationcom_jhotelreservation1High2019-01-01
jNewscom_jnews1High2020-03-09
Jomrescom_jomres1High2026-05-23
JoomCRMcom_joomcrm1High2019-01-01
Joomdlecom_joomdle1High2026-07-28
LDAP Integration with Active Directorycom_miniorange_dirsync1High2023-01-17
LMS King Professionalcom_lmsking1High2017-01-01
MyPortfoliocom_myportfolio1High2017-01-01
paGO Commercecom_pago1High2020-09-18
PHP-Bridgecom_phpbridge1High2017-01-01
Quix Page Buildercom_quix1High2026-07-15
Regular Labs DB Replacercom_dbreplacer1High2026-07-22
Regular Labs Extension Managercom_regularlabsmanager1High2026-07-22
Regular Labs IP Loginiplogin1High2026-07-22
RO CSVIcom_csvi1High2026-07-28
S5 Registermod_s5_register1High2023-12-14
StreetGuessr Gamecom_streetguess1High2017-01-01
Survey Force Deluxecom_surveyforce1High2026-06-19
Twitch TVcom_twitchtv1High2017-01-01
Ultimate Property Listingcom_upl1High2017-01-01
vAccountcom_vaccount1High2019-01-01
vBizzcom_vbizz1High2019-01-01
VMapcom_vmap1High2019-01-01
vReviewcom_vreview1High2019-01-01
vWishlistcom_vwishlist1High2019-01-01
Phoca Mapscom_phocamaps2Medium2026-07-23
Balbooa Gallerycom_bagallery1Medium2025-07-18
Balbooa Gallerycom_gallery1Medium2026-08-18
Booking - Book Itcom_booking1Medium2023-01-01
CCommentcom_comment1Medium2025-07-23
Clicky Analytics Dashboardmod_clicky_dash1Medium2023-12-14
DJ-HelpfulArticlescom_djhelpfularticles1Medium2024-07-09
Easy Quick Contactmod_easyquickcontact1Medium2023-12-14
iProperty Real Estatecom_iproperty1Medium2026-04-09
JLex Reviewcom_jlexreview1Medium2026-04-09
JoomProjectcom_jpprojects1Medium2019-01-01
JoomShoppingcom_jshopping1Medium2026-07-22
LivingWordcom_livingword1Medium2023-12-14
Membership Procom_osmembership1Medium2026-07-21
oneVotecom_onevote1Medium2023-07-11
osTicky2com_osticky21Medium2024-02-15
Phoca Guestbookcom_phocaguestbook1Medium2026-07-23
Regular Labs Advanced Module Managercom_advancedmodules1Medium2026-07-22
Regular Labs Better Frontend Linkmod_betterfrontendlink1Medium2026-07-22
Regular Labs CDNcdnforjoomla1Medium2026-07-22
Regular Labs Conditional Contentconditionalcontent1Medium2026-07-22
Regular Labs Content Templatercom_contenttemplater1Medium2026-07-22
Regular Labs Email Protectoremailprotector1Medium2026-07-22
Regular Labs Quick Indexquickindex1Medium2026-07-22
Regular Labs ReReplacercom_rereplacer1Medium2026-07-22
Regular Labs Snippetscom_snippets1Medium2026-07-22
Regular Labs Tabs & Accordionstabsaccordions1Medium2026-07-22
RSBlog!com_rsblog1Medium2025-01-01
Solidrescom_solidres1Medium2026-04-09
XCloner Backupcom_xcloner-backupandrestore1Medium2020-05-23
HikaShopcom_hikashop1Low2026-07-20
J2Store / J2Commercecom_j2store3Unrated-
SEBLODcom_cck3Unrated-
ZOOcom_zoo3Unrated-
Cotton Cloudcom_cotton2Unrated-
Fabrikcom_fabrik2Unrated-
YOOtheme Proyootheme2Unrated-
Admiror Gallerycom_admirorgallery1Unrated-
Ajax Quizcom_ajaxquiz1Unrated-
Articles Anywherearticlesanywhere1Unrated-
Cache Cleanercachecleaner1Unrated-
CommentBoxcom_commentbox1Unrated-
Creative Gallerycom_creativegallery1Unrated-
DJ-Flyercom_djflyer1Unrated-
DJ-Reviewscom_djreviews1Unrated-
DOCmancom_docman1Unrated-
eXtplorercom_extplorer1Unrated-
FocalPointcom_focalpoint1Unrated-
Gurucom_guru1Unrated-
iCagenda Calendar modulemod_icagenda_calendar1Unrated-
JCDashboardscom_jcdashboards1Unrated-
JEM - Joomla Event Managercom_jem1Unrated-
JMediacom_jmedia1Unrated-
JoomDOCcom_joomdoc1Unrated-
JoomGallerycom_joomgallery1Unrated-
Joomla Quiz Deluxecom_joomlaquiz1Unrated-
JoomRecipecom_joomrecipe1Unrated-
JS Jobscom_jsjobs1Unrated-
Keyboard Shortcutskeyboardshortcuts1Unrated-
Komentocom_komento1Unrated-
Modalsmodals1Unrated-
Modules Anywheremodulesanywhere1Unrated-
No Boss Calendarcom_nobosscalendar1Unrated-
No Boss Testimonialscom_nobosstestimonials1Unrated-
OSDownloadscom_osdownloads1Unrated-
Payagecom_payage1Unrated-
ProFilescom_profiles1Unrated-
Proforms Basiccom_proforms1Unrated-
Quantum Managercom_quantummanager1Unrated-
QuickFormcom_quickform1Unrated-
RSDirectory!com_rsdirectory1Unrated-
RSFirewall!com_rsfirewall1Unrated-
RSMail!com_rsmail1Unrated-
RSMediaGallery!com_rsmediagallery1Unrated-
RSTickets! Procom_rsticketspro1Unrated-
SIMGenealogycom_simgenealogy1Unrated-
SP Movie Databasecom_spmoviedb1Unrated-
SP Property Findercom_spproperty1Unrated-
Sponsor Wallcom_sponsorwall1Unrated-
Tooltipstooltips1Unrated-
Users Anywhereusersanywhere1Unrated-
VirtueMartcom_virtuemart1Unrated-
Zap Calendarcom_zcalendar1Unrated-

Vulnerabilities we found and disclosed

61 write-ups. Every one was reported privately to the developer first.

A CVSS 10.0 Account Takeover in miniOrange OAuth Client for Joomla, Fixed in 3.2.0

miniOrange OAuth Client for Joomla below 3.2.0 lets an unauthenticated visitor change one cookie value and log in as any account, administrators included. It is scored CVSS 10.0 and fixed in 3.2.0. The same vendor shipped near-identical auth bypasses on the WordPress side days earlier.

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

Fabrik 4.7.2 for Joomla closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Here is the full list and what to do.

Five Security Issues in JEM (Joomla Event Manager), and No Stable Fix Yet

mySites.guru found and reported multiple security issues in JEM (Joomla Event Manager), including an unauthenticated article overwrite. Five CVEs are assigned. There is no stable fix yet, so here is what to do.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66

YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus an unauthenticated SQL injection. Those are fixed in 4.1.64. Two more releases followed inside three days, closing five more issues between them, one of them scored 8.6. Install 4.1.66.

iCagenda 4.0.12 fixes an unauthenticated SQL injection

CVE-2026-67365 is an unauthenticated SQL injection in the iCagenda Calendar module for Joomla, scored 9.2 Critical. Fixed in 4.0.12.

Sourcerer 14.0.0 fixes PHP execution from unverified content

Sourcerer, the Joomla extension, ran PHP from page content it could not trace to a verified source. CVE-2026-74253 scores 10.0 critical. Update to 14.0.0.

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 sites running Phoca Cart 6.x are not offered it.

Unauthenticated Remote Code Execution in SP Page Builder found by mySites.guru

mySites.guru found a pre-authentication remote code execution flaw in SP Page Builder for Joomla, in the same 6.7.1 release that fixed our earlier reports. Update to 6.8.0 now.

Cotton Cloud Patched the Login, Then the Data

Two access control flaws in Cotton Cloud for Joomla. The first fix closed the door and left the room unlocked. CVE-2026-67283 and CVE-2026-67284 are fixed in 2.0.3.

Twenty Rules for Joomla Extension Developers Handling a Security Report

A new Joomla Manual page sets out 20 rules for how extension developers should handle a security report. Republished here in full under the JEDL.

The Fabrik Fiasco: Announced, Restricted, Relabelled

Two CVSS 10.0 RCEs in the Fabrik Joomla extension, and a chaotic run of security releases. The vendor has since moved past 4.7.0; the current release to be on is 4.7.2.

Another 23 Critical Security Vulnerabilities in Gridbox for Joomla

Balbooa asked us to audit Gridbox. We found 23 vulnerabilities, including a pre-auth RCE in one request. Several are being actively exploited in the wild, and the complete fix is now out in Gridbox 2.20.2. Update every Gridbox site immediately.

Every disclosure we have published