Joomla extension vulnerabilities
These are the 215 vulnerability rules mySites.guru checks every connected Joomla site against, covering 162 extensions. A good number of them exist because we found the flaw ourselves and reported it to the developer before publishing.
Rules current as of 24 August 2026. Subscribers see which of their own sites are affected, on the site's Manage page.
Extensions we track
Filter by severity, or search for the extension you run.
| Extension | Rules | Severity | Latest |
|---|---|---|---|
| Page Builder CKcom_pagebuilderck | 8 | Critical, High, Medium | 2026-08-17 |
| Phoca Cartcom_phocacart | 6 | Critical, Medium | - |
| Events Bookingcom_eventbooking | 3 | Critical, Medium | 2026-07-20 |
| iCagendacom_icagenda | 3 | Critical | 2026-06-15 |
| J-BusinessDirectorycom_jbusinessdirectory | 3 | Critical | 2026-08-19 |
| JCEcom_jce | 3 | Critical, High, Medium | 2026-07-29 |
| Phoca Downloadcom_phocadownload | 3 | Critical, High, Medium | 2026-07-10 |
| SP Page Buildercom_sppagebuilder | 3 | Critical | 2026-07-27 |
| Balbooa Formscom_baforms | 2 | Critical | 2026-08-18 |
| Easy Folder Listing Procom_easyfolderlistingpro | 2 | Critical | 2024-11-26 |
| Gridboxcom_gridbox | 2 | Critical | 2026-08-10 |
| Helix Ultimateshaper_helixultimate | 2 | Critical | 2026-07-07 |
| Helix Ultimate Frameworkhelixultimate | 2 | Critical | 2026-07-07 |
| jDownloadscom_jdownloads | 2 | Critical, Medium | 2026-07-17 |
| JEventscom_jevents | 2 | Critical | 2025-01-01 |
| Smart Slider 3 Prosmartslider3 | 2 | Critical, Medium | 2026-04-08 |
| Sourcerersourcerer | 2 | Critical | 2026-08-17 |
| AcyMailingcom_acym | 1 | Critical | 2026-07-09 |
| Aimy Captcha-Less Form Guardaimycaptchalessformguard | 1 | Critical | 2026-07-28 |
| Articles Calendarmod_articles_calendar | 1 | Critical | 2025-07-18 |
| Articles Calendararticlescalendar | 1 | Critical | 2025-07-18 |
| Astroid Frameworkastroid | 1 | Critical | 2026-03-05 |
| BrainCert Virtual Classroomcom_virtualclassroom | 1 | Critical | 2023-08-07 |
| Creative Contact Formcom_creativecontactform | 1 | Critical | 2020-03-04 |
| DJ-Classifiedscom_djclassifieds | 1 | Critical | 2026-07-20 |
| EDocmancom_edocman | 1 | Critical | 2026-07-14 |
| Helix3 Templateshaper_helix3 | 1 | Critical | 2026-06-29 |
| JoomCCKcom_joomcck | 1 | Critical | 2026-07-17 |
| K2com_k2 | 1 | Critical | 2026-01-01 |
| LMS Litecom_lmslite | 1 | Critical | 2023-12-14 |
| RSFiles!com_rsfiles | 1 | Critical | 2026-07-10 |
| RSForm!Procom_rsform | 1 | Critical | 2025-01-01 |
| SP LMScom_splms | 1 | Critical | 2026-01-01 |
| Starshopcom_starshop | 1 | Critical | 2023-12-14 |
| Visitors Countermod_vvisit_counter | 1 | Critical | 2025-10-03 |
| Convert Formscom_convertforms | 5 | High | 2026-07-23 |
| Visformscom_visforms | 4 | High | - |
| DPCalendarcom_dpcalendar | 3 | High, Medium | 2026-07-13 |
| Phoca Commandercom_phocacommander | 2 | High | 2026-07-27 |
| 4Analyticscom_foranalytics | 1 | High | 2026-07-15 |
| AcyMailingcom_acymailing | 1 | High | 2020-03-09 |
| Admiror Framesadmirorframes | 1 | High | 2024-06-28 |
| ChronoForms 8com_chronoforms8 | 1 | High | 2026-07-17 |
| Easy Shopcom_easyshop | 1 | High | 2019-01-01 |
| EasyDiscusscom_easydiscuss | 1 | High | 2026-01-16 |
| EasyStorecom_easystore | 1 | High | - |
| Event Registration Pro Calendarcom_registrationpro | 1 | High | 2017-01-01 |
| Extra Searchcom_extrasearch | 1 | High | 2017-01-01 |
| Flip Wallcom_flipwall | 1 | High | 2026-06-19 |
| HDW Playercom_hdwplayer | 1 | High | 2026-05-13 |
| Ignite Gallerycom_igallery | 1 | High | 2026-07-07 |
| J-ClassifiedsManagercom_displayads | 1 | High | 2019-01-01 |
| J-MultipleHotelReservationcom_jmultiplehotelreservation | 1 | High | 2019-01-01 |
| jCartcom_jcart | 1 | High | 2017-01-01 |
| JHotelReservationcom_jhotelreservation | 1 | High | 2019-01-01 |
| jNewscom_jnews | 1 | High | 2020-03-09 |
| Jomrescom_jomres | 1 | High | 2026-05-23 |
| JoomCRMcom_joomcrm | 1 | High | 2019-01-01 |
| Joomdlecom_joomdle | 1 | High | 2026-07-28 |
| LDAP Integration with Active Directorycom_miniorange_dirsync | 1 | High | 2023-01-17 |
| LMS King Professionalcom_lmsking | 1 | High | 2017-01-01 |
| MyPortfoliocom_myportfolio | 1 | High | 2017-01-01 |
| paGO Commercecom_pago | 1 | High | 2020-09-18 |
| PHP-Bridgecom_phpbridge | 1 | High | 2017-01-01 |
| Quix Page Buildercom_quix | 1 | High | 2026-07-15 |
| Regular Labs DB Replacercom_dbreplacer | 1 | High | 2026-07-22 |
| Regular Labs Extension Managercom_regularlabsmanager | 1 | High | 2026-07-22 |
| Regular Labs IP Loginiplogin | 1 | High | 2026-07-22 |
| RO CSVIcom_csvi | 1 | High | 2026-07-28 |
| S5 Registermod_s5_register | 1 | High | 2023-12-14 |
| StreetGuessr Gamecom_streetguess | 1 | High | 2017-01-01 |
| Survey Force Deluxecom_surveyforce | 1 | High | 2026-06-19 |
| Twitch TVcom_twitchtv | 1 | High | 2017-01-01 |
| Ultimate Property Listingcom_upl | 1 | High | 2017-01-01 |
| vAccountcom_vaccount | 1 | High | 2019-01-01 |
| vBizzcom_vbizz | 1 | High | 2019-01-01 |
| VMapcom_vmap | 1 | High | 2019-01-01 |
| vReviewcom_vreview | 1 | High | 2019-01-01 |
| vWishlistcom_vwishlist | 1 | High | 2019-01-01 |
| Phoca Mapscom_phocamaps | 2 | Medium | 2026-07-23 |
| Balbooa Gallerycom_bagallery | 1 | Medium | 2025-07-18 |
| Balbooa Gallerycom_gallery | 1 | Medium | 2026-08-18 |
| Booking - Book Itcom_booking | 1 | Medium | 2023-01-01 |
| CCommentcom_comment | 1 | Medium | 2025-07-23 |
| Clicky Analytics Dashboardmod_clicky_dash | 1 | Medium | 2023-12-14 |
| DJ-HelpfulArticlescom_djhelpfularticles | 1 | Medium | 2024-07-09 |
| Easy Quick Contactmod_easyquickcontact | 1 | Medium | 2023-12-14 |
| iProperty Real Estatecom_iproperty | 1 | Medium | 2026-04-09 |
| JLex Reviewcom_jlexreview | 1 | Medium | 2026-04-09 |
| JoomProjectcom_jpprojects | 1 | Medium | 2019-01-01 |
| JoomShoppingcom_jshopping | 1 | Medium | 2026-07-22 |
| LivingWordcom_livingword | 1 | Medium | 2023-12-14 |
| Membership Procom_osmembership | 1 | Medium | 2026-07-21 |
| oneVotecom_onevote | 1 | Medium | 2023-07-11 |
| osTicky2com_osticky2 | 1 | Medium | 2024-02-15 |
| Phoca Guestbookcom_phocaguestbook | 1 | Medium | 2026-07-23 |
| Regular Labs Advanced Module Managercom_advancedmodules | 1 | Medium | 2026-07-22 |
| Regular Labs Better Frontend Linkmod_betterfrontendlink | 1 | Medium | 2026-07-22 |
| Regular Labs CDNcdnforjoomla | 1 | Medium | 2026-07-22 |
| Regular Labs Conditional Contentconditionalcontent | 1 | Medium | 2026-07-22 |
| Regular Labs Content Templatercom_contenttemplater | 1 | Medium | 2026-07-22 |
| Regular Labs Email Protectoremailprotector | 1 | Medium | 2026-07-22 |
| Regular Labs Quick Indexquickindex | 1 | Medium | 2026-07-22 |
| Regular Labs ReReplacercom_rereplacer | 1 | Medium | 2026-07-22 |
| Regular Labs Snippetscom_snippets | 1 | Medium | 2026-07-22 |
| Regular Labs Tabs & Accordionstabsaccordions | 1 | Medium | 2026-07-22 |
| RSBlog!com_rsblog | 1 | Medium | 2025-01-01 |
| Solidrescom_solidres | 1 | Medium | 2026-04-09 |
| XCloner Backupcom_xcloner-backupandrestore | 1 | Medium | 2020-05-23 |
| HikaShopcom_hikashop | 1 | Low | 2026-07-20 |
| J2Store / J2Commercecom_j2store | 3 | Unrated | - |
| SEBLODcom_cck | 3 | Unrated | - |
| ZOOcom_zoo | 3 | Unrated | - |
| Cotton Cloudcom_cotton | 2 | Unrated | - |
| Fabrikcom_fabrik | 2 | Unrated | - |
| YOOtheme Proyootheme | 2 | Unrated | - |
| Admiror Gallerycom_admirorgallery | 1 | Unrated | - |
| Ajax Quizcom_ajaxquiz | 1 | Unrated | - |
| Articles Anywherearticlesanywhere | 1 | Unrated | - |
| Cache Cleanercachecleaner | 1 | Unrated | - |
| CommentBoxcom_commentbox | 1 | Unrated | - |
| Creative Gallerycom_creativegallery | 1 | Unrated | - |
| DJ-Flyercom_djflyer | 1 | Unrated | - |
| DJ-Reviewscom_djreviews | 1 | Unrated | - |
| DOCmancom_docman | 1 | Unrated | - |
| eXtplorercom_extplorer | 1 | Unrated | - |
| FocalPointcom_focalpoint | 1 | Unrated | - |
| Gurucom_guru | 1 | Unrated | - |
| iCagenda Calendar modulemod_icagenda_calendar | 1 | Unrated | - |
| JCDashboardscom_jcdashboards | 1 | Unrated | - |
| JEM - Joomla Event Managercom_jem | 1 | Unrated | - |
| JMediacom_jmedia | 1 | Unrated | - |
| JoomDOCcom_joomdoc | 1 | Unrated | - |
| JoomGallerycom_joomgallery | 1 | Unrated | - |
| Joomla Quiz Deluxecom_joomlaquiz | 1 | Unrated | - |
| JoomRecipecom_joomrecipe | 1 | Unrated | - |
| JS Jobscom_jsjobs | 1 | Unrated | - |
| Keyboard Shortcutskeyboardshortcuts | 1 | Unrated | - |
| Komentocom_komento | 1 | Unrated | - |
| Modalsmodals | 1 | Unrated | - |
| Modules Anywheremodulesanywhere | 1 | Unrated | - |
| No Boss Calendarcom_nobosscalendar | 1 | Unrated | - |
| No Boss Testimonialscom_nobosstestimonials | 1 | Unrated | - |
| OSDownloadscom_osdownloads | 1 | Unrated | - |
| Payagecom_payage | 1 | Unrated | - |
| ProFilescom_profiles | 1 | Unrated | - |
| Proforms Basiccom_proforms | 1 | Unrated | - |
| Quantum Managercom_quantummanager | 1 | Unrated | - |
| QuickFormcom_quickform | 1 | Unrated | - |
| RSDirectory!com_rsdirectory | 1 | Unrated | - |
| RSFirewall!com_rsfirewall | 1 | Unrated | - |
| RSMail!com_rsmail | 1 | Unrated | - |
| RSMediaGallery!com_rsmediagallery | 1 | Unrated | - |
| RSTickets! Procom_rsticketspro | 1 | Unrated | - |
| SIMGenealogycom_simgenealogy | 1 | Unrated | - |
| SP Movie Databasecom_spmoviedb | 1 | Unrated | - |
| SP Property Findercom_spproperty | 1 | Unrated | - |
| Sponsor Wallcom_sponsorwall | 1 | Unrated | - |
| Tooltipstooltips | 1 | Unrated | - |
| Users Anywhereusersanywhere | 1 | Unrated | - |
| VirtueMartcom_virtuemart | 1 | Unrated | - |
| Zap Calendarcom_zcalendar | 1 | Unrated | - |
No extension matches that.
Vulnerabilities we found and disclosed
61 write-ups. Every one was reported privately to the developer first.

A CVSS 10.0 Account Takeover in miniOrange OAuth Client for Joomla, Fixed in 3.2.0
miniOrange OAuth Client for Joomla below 3.2.0 lets an unauthenticated visitor change one cookie value and log in as any account, administrators included. It is scored CVSS 10.0 and fixed in 3.2.0. The same vendor shipped near-identical auth bypasses on the WordPress side days earlier.

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes
Fabrik 4.7.2 for Joomla closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Here is the full list and what to do.

Five Security Issues in JEM (Joomla Event Manager), and No Stable Fix Yet
mySites.guru found and reported multiple security issues in JEM (Joomla Event Manager), including an unauthenticated article overwrite. Five CVEs are assigned. There is no stable fix yet, so here is what to do.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66
YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus an unauthenticated SQL injection. Those are fixed in 4.1.64. Two more releases followed inside three days, closing five more issues between them, one of them scored 8.6. Install 4.1.66.

iCagenda 4.0.12 fixes an unauthenticated SQL injection
CVE-2026-67365 is an unauthenticated SQL injection in the iCagenda Calendar module for Joomla, scored 9.2 Critical. Fixed in 4.0.12.

Sourcerer 14.0.0 fixes PHP execution from unverified content
Sourcerer, the Joomla extension, ran PHP from page content it could not trace to a verified source. CVE-2026-74253 scores 10.0 critical. Update to 14.0.0.

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection
Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 sites running Phoca Cart 6.x are not offered it.

Unauthenticated Remote Code Execution in SP Page Builder found by mySites.guru
mySites.guru found a pre-authentication remote code execution flaw in SP Page Builder for Joomla, in the same 6.7.1 release that fixed our earlier reports. Update to 6.8.0 now.

Cotton Cloud Patched the Login, Then the Data
Two access control flaws in Cotton Cloud for Joomla. The first fix closed the door and left the room unlocked. CVE-2026-67283 and CVE-2026-67284 are fixed in 2.0.3.

Twenty Rules for Joomla Extension Developers Handling a Security Report
A new Joomla Manual page sets out 20 rules for how extension developers should handle a security report. Republished here in full under the JEDL.

The Fabrik Fiasco: Announced, Restricted, Relabelled
Two CVSS 10.0 RCEs in the Fabrik Joomla extension, and a chaotic run of security releases. The vendor has since moved past 4.7.0; the current release to be on is 4.7.2.

Another 23 Critical Security Vulnerabilities in Gridbox for Joomla
Balbooa asked us to audit Gridbox. We found 23 vulnerabilities, including a pre-auth RCE in one request. Several are being actively exploited in the wild, and the complete fix is now out in Gridbox 2.20.2. Update every Gridbox site immediately.