Joomla Vulnerability Database
These are the 343 vulnerability rules mySites.guru checks every connected Joomla site against, covering 204 extensions and 418 CVE-numbered vulnerabilities. A good number of them exist because we found the flaw ourselves and reported it to the developer before publishing.
Rules current as of 3 October 2026. Subscribers see which of their own sites are affected, on the site's Manage page.
Why no WordPress CVE or vulnerability data?
WordPress is covered by the service too: mySites.guru integrates Wordfence's vulnerability feed in full, mirroring the data published on Wordfence's vulnerability pages, and every connected WordPress site is checked against it on each audit. To research a WordPress plugin or theme yourself, search Wordfence's database directly.
Subscribe by RSS
New rules as we start checking sites against them. One item per rule, so a CVE needing a rule per Joomla branch appears once for each.
https://mysites.guru/vulnerabilities/rss.xml This page is public. Acting on it across a portfolio is the mySites.guru subscription: each audit checks every connected Joomla and WordPress site against these rules, flags the ones running an affected version, and updates the extension in one click across all of them. One price, unlimited sites, 90,000+ sites protected in 14 years.
Extensions we track
Filter by severity, or search for the extension or CVE you're after. Browse every tracked CVE at the Joomla CVE index.
| Extension | Rules | Severity | Latest | CVEs |
|---|---|---|---|---|
| Page Builder CKcom_pagebuilderck | 10 | Critical, High, Medium | 2026-08-17 | CVE-2026-74254CVE-2026-77993CVE-2026-77994CVE-2026-63048CVE-2026-62414CVE-2026-56290 |
| J2Store / J2Commercecom_j2store | 9 | Critical, High | 2026-09-15 | CVE-2026-78081CVE-2026-81567CVE-2026-81568CVE-2026-82189CVE-2026-82190CVE-2026-82191CVE-2026-77999CVE-2026-78000CVE-2026-78064CVE-2026-78065CVE-2026-78069CVE-2026-67358CVE-2026-67359CVE-2026-67360CVE-2026-67361CVE-2026-67362CVE-2026-74252CVE-2020-13996 |
| Phoca Cartcom_phocacart | 7 | Critical, High, Medium | 2026-10-01 | CVE-2026-74251CVE-2026-76564CVE-2026-76565 |
| miniOrange SAML SSOcom_miniorange_saml | 6 | Critical, High | 2026-08-31 | CVE-2026-78074CVE-2026-77998 |
| Phoca Downloadcom_phocadownload | 6 | Critical, High, Medium | 2026-07-10 | CVE-2026-57828CVE-2026-76569 |
| miniOrange OAuth Clientcom_miniorange_oauth | 4 | Critical, High | 2026-08-31 | CVE-2026-78074CVE-2026-77995 |
| SP Page Buildercom_sppagebuilder | 4 | Critical, High | 2026-09-14 | CVE-2026-78375CVE-2026-79700CVE-2026-79701CVE-2026-81564CVE-2026-81565CVE-2026-81566CVE-2026-67285CVE-2026-67286CVE-2026-67287CVE-2026-65876CVE-2026-65766CVE-2026-65877CVE-2026-66494CVE-2026-65878CVE-2026-65879CVE-2026-48908 |
| Articles Anywherearticlesanywhere | 3 | Critical, High | 2026-09-13 | CVE-2026-85195CVE-2026-85196CVE-2026-64793CVE-2026-64794CVE-2026-64795CVE-2026-64799CVE-2026-65755 |
| Balbooa Formscom_baforms | 3 | Critical | 2026-09-29 | CVE-2026-102425CVE-2026-102424CVE-2026-101127CVE-2026-101112CVE-2026-101126CVE-2026-67364CVE-2026-67363CVE-2026-65880CVE-2026-56291CVE-2025-49485 |
| Conditional Contentconditionalcontent | 3 | Critical, Medium | 2026-09-13 | CVE-2026-85192CVE-2026-85188CVE-2026-63280CVE-2026-63281CVE-2026-63683CVE-2026-64792 |
| Events Bookingcom_eventbooking | 3 | Critical, Medium | 2026-07-20 | CVE-2026-63047CVE-2026-58149CVE-2026-60024CVE-2026-60025 |
| Gridboxcom_gridbox | 3 | Critical, High | 2026-09-21 | CVE-2026-61425CVE-2026-65884CVE-2026-65885CVE-2026-65889CVE-2026-65890CVE-2026-66488CVE-2026-66489CVE-2026-66490CVE-2026-65886CVE-2026-65887CVE-2026-65888CVE-2026-65947 |
| Helix Ultimateshaper_helixultimate | 3 | Critical, High | 2026-08-31 | CVE-2026-78075CVE-2026-78076CVE-2026-78077CVE-2026-78078CVE-2026-78079CVE-2026-57829CVE-2026-57830 |
| Helix Ultimate Frameworkhelixultimate | 3 | Critical, High | 2026-08-31 | CVE-2026-78075CVE-2026-78076CVE-2026-78077CVE-2026-78078CVE-2026-78079CVE-2026-57829CVE-2026-57830 |
| iCagendacom_icagenda | 3 | Critical | 2026-06-15 | CVE-2026-48939CVE-2026-67365CVE-2026-71571CVE-2026-67366CVE-2026-71570 |
| J-BusinessDirectorycom_jbusinessdirectory | 3 | Critical | 2026-08-19 | CVE-2026-75949CVE-2026-75954CVE-2026-75956CVE-2026-75950CVE-2026-75951CVE-2026-75952CVE-2026-75953CVE-2026-75955CVE-2020-5182CVE-2019-25752 |
| JCEcom_jce | 3 | Critical, High, Medium | 2026-07-29 | CVE-2026-65891CVE-2026-48907CVE-2015-7339 |
| Modules Anywheremodulesanywhere | 3 | Critical, High | 2026-09-27 | CVE-2026-100750CVE-2026-65757CVE-2026-64793CVE-2026-64795 |
| Sourcerersourcerer | 3 | Critical, Low | 2026-08-17 | CVE-2026-74253CVE-2025-22204CVE-2026-64796 |
| ZOOcom_zoo | 3 | Critical, High, Medium | 2026-08-21 | CVE-2026-76611CVE-2026-76612CVE-2026-77028CVE-2026-77029CVE-2026-76610CVE-2026-74803CVE-2026-74804CVE-2026-75114 |
| AcyMailingcom_acym | 2 | Critical | 2026-09-24 | CVE-2026-94132CVE-2026-94131CVE-2026-56292CVE-2023-39970CVE-2023-39971CVE-2023-39972CVE-2023-39973CVE-2023-39974 |
| Astroid Frameworkastroid | 2 | Critical | 2026-03-05 | CVE-2026-21628 |
| Book Librarycom_booklibrary | 2 | Critical, Medium | 2026-09-28 | CVE-2026-101111CVE-2026-101110 |
| Easy Folder Listing Procom_easyfolderlistingpro | 2 | Critical | 2024-11-26 | CVE-2024-11145 |
| Fabrikcom_fabrik | 2 | Critical, High | 2026-08-22 | CVE-2026-76571CVE-2026-76596CVE-2026-76597CVE-2026-76598CVE-2026-76600CVE-2026-76601CVE-2026-76602CVE-2026-76603CVE-2026-76604CVE-2026-76605CVE-2026-76606CVE-2026-76607CVE-2026-76608CVE-2026-76609CVE-2026-77027CVE-2026-77992CVE-2026-76599CVE-2020-37219CVE-2026-67282CVE-2026-66915 |
| jDownloadscom_jdownloads | 2 | Critical, Medium | 2026-07-17 | CVE-2026-61900CVE-2025-55758CVE-2022-27909 |
| JEventscom_jevents | 2 | Critical | 2025-01-01 | CVE-2025-49467CVE-2015-7340 |
| K2com_k2 | 2 | Critical, Medium | 2026-06-25 | CVE-2026-48941CVE-2026-48942CVE-2026-48943CVE-2026-48944CVE-2026-48945CVE-2026-48946CVE-2026-48940 |
| OS CCKcom_os_cck | 2 | Critical, High | 2026-09-30 | CVE-2026-102427 |
| OS Gallerycom_osgallery | 2 | Critical | 2026-09-20 | CVE-2026-88854CVE-2026-88857CVE-2026-88856CVE-2026-88855 |
| Real Estate Managercom_realestatemanager | 2 | Critical, Medium | 2026-09-28 | CVE-2026-100753CVE-2026-100752 |
| Smart Slider 3 Prosmartslider3 | 2 | Critical, Medium | 2026-04-08 | CVE-2026-34424 |
| UP Universal Pluginup | 2 | Critical | 2026-09-26 | CVE-2026-97160CVE-2026-97161CVE-2026-97162CVE-2026-97163 |
| Vehicle Managercom_vehiclemanager | 2 | Critical, Medium | 2026-09-28 | CVE-2026-101109CVE-2026-101108 |
| Aimy Captcha-Less Form Guardaimycaptchalessformguard | 1 | Critical | 2026-07-28 | CVE-2026-65883 |
| Articles Calendarmod_articles_calendar | 1 | Critical | 2025-07-18 | CVE-2025-26855 |
| Articles Calendararticlescalendar | 1 | Critical | 2025-07-18 | CVE-2025-26855 |
| BrainCert Virtual Classroomcom_virtualclassroom | 1 | Critical | 2023-08-07 | CVE-2023-34477 |
| Conditional Contentpkg_conditionalcontent | 1 | Critical | 2026-09-13 | CVE-2026-85192CVE-2026-85188 |
| Creative Contact Formcom_creativecontactform | 1 | Critical | 2020-03-04 | CVE-2014-8739CVE-2020-9364 |
| DJ-Classifiedscom_djclassifieds | 1 | Critical | 2026-07-20 | CVE-2026-61424CVE-2025-54474 |
| EDocmancom_edocman | 1 | Critical | 2026-07-14 | CVE-2026-57832 |
| Helix3 Templateshaper_helix3 | 1 | Critical | 2026-06-29 | CVE-2026-49049 |
| JCTablescom_jctables | 1 | Critical | 2026-09-30 | CVE-2026-76570 |
| JEM - Joomla Event Managercom_jem | 1 | Critical | 2026-08-27 | CVE-2026-77034CVE-2026-77035CVE-2026-77989CVE-2026-77990CVE-2026-77991 |
| JooDatabasecom_joodb | 1 | Critical | 2026-09-03 | CVE-2026-78080 |
| JoomCCKcom_joomcck | 1 | Critical | 2026-07-17 | CVE-2026-49048 |
| LMS Litecom_lmslite | 1 | Critical | 2023-12-14 | CVE-2023-40629 |
| Regular Labs GeoIPgeoip | 1 | Critical | 2026-07-23 | CVE-2026-65431CVE-2026-64876CVE-2026-65430CVE-2026-64875 |
| RSFiles!com_rsfiles | 1 | Critical | 2026-07-10 | CVE-2026-57827CVE-2025-50057 |
| RSForm!Procom_rsform | 1 | Critical | 2025-01-01 | CVE-2025-30085CVE-2025-27444 |
| SP LMScom_splms | 1 | Critical | 2026-01-01 | CVE-2026-48909 |
| SP Property Findercom_spproperty | 1 | Critical | 2026-09-10 | CVE-2026-78082CVE-2026-78303CVE-2026-78083CVE-2026-78084CVE-2026-78302CVE-2026-78085 |
| Starshopcom_starshop | 1 | Critical | 2023-12-14 | CVE-2023-49708 |
| Visitors Countermod_vvisit_counter | 1 | Critical | 2025-10-03 | CVE-2025-40636 |
| YouTube Gallerycom_youtubegallery | 1 | Critical | 2026-09-26 | CVE-2026-94130 |
| Snippetscom_snippets | 9 | High, Medium | 2026-09-13 | CVE-2026-88852CVE-2026-63684CVE-2026-64792CVE-2026-63265 |
| DPCalendarcom_dpcalendar | 7 | High, Medium | 2026-08-28 | CVE-2026-78071CVE-2026-78070CVE-2026-57831CVE-2024-21727 |
| YOOtheme Proyootheme | 6 | High, Medium | 2026-08-25 | CVE-2026-77997CVE-2026-76613CVE-2026-75115 |
| Convert Formscom_convertforms | 5 | High | 2026-07-23 | CVE-2026-65758CVE-2024-40744CVE-2024-40745CVE-2025-22212CVE-2026-77026 |
| Tabs & Accordionstabsaccordions | 5 | High, Medium | 2026-09-27 | CVE-2026-100751CVE-2026-85191CVE-2026-64792CVE-2026-63265 |
| Visformscom_visforms | 4 | High | - | CVE-2023-23753 |
| Modalsmodals | 3 | High | 2026-09-13 | CVE-2026-85189CVE-2026-88853CVE-2026-65713 |
| Quix Page Buildercom_quix | 3 | High | 2026-07-15 | CVE-2026-58078CVE-2026-60026CVE-2026-60027CVE-2026-60028CVE-2026-60029CVE-2026-60030CVE-2026-60031 |
| EasyStorecom_easystore | 2 | High | 2026-09-23 | CVE-2026-90899CVE-2026-90900CVE-2026-90901CVE-2026-90902CVE-2026-90903CVE-2026-90904CVE-2026-90905CVE-2026-65759CVE-2026-65760CVE-2026-65761 |
| JoomGallerycom_joomgallery | 2 | High, Medium | 2026-09-15 | CVE-2026-84048CVE-2026-66917CVE-2026-66916 |
| miniOrange LDAP Integrationcom_miniorange_dirsync | 2 | High | 2026-08-31 | CVE-2026-78074CVE-2023-23749 |
| Phoca Commandercom_phocacommander | 2 | High | 2026-07-27 | CVE-2026-65764CVE-2026-65765CVE-2025-54473CVE-2026-66491CVE-2026-66492CVE-2026-66493 |
| Quick Indexquickindex | 2 | High, Medium | 2026-09-13 | CVE-2026-85190CVE-2026-63265 |
| Sexy Polling Reloadedcom_sexypolling | 2 | High | 2026-08-28 | CVE-2026-78072 |
| Snippetspkg_snippets | 2 | High | 2026-09-13 | CVE-2026-88852 |
| Tabs & Accordionspkg_tabsaccordions | 2 | High | 2026-09-27 | CVE-2026-100751CVE-2026-85191 |
| Users Anywhereusersanywhere | 2 | High, Medium | 2026-09-13 | CVE-2026-85196CVE-2026-64794CVE-2026-64795CVE-2026-64799CVE-2026-65755 |
| YOOtheme Prolocation | 2 | High | 2026-08-25 | CVE-2026-77996 |
| 4Analyticscom_foranalytics | 1 | High | 2026-07-15 | CVE-2026-58077CVE-2026-57833 |
| AcyMailingcom_acymailing | 1 | High | 2020-03-09 | CVE-2015-7338 |
| Admiror Framesadmirorframes | 1 | High | 2024-06-28 | CVE-2024-5735CVE-2024-5736CVE-2024-5737 |
| Articles Anywherepkg_articlesanywhere | 1 | High | 2026-09-13 | CVE-2026-85195CVE-2026-85196 |
| ChronoForms 8com_chronoforms8 | 1 | High | 2026-07-17 | CVE-2026-58148 |
| DPAttachmentscom_dpattachments | 1 | High | 2026-09-10 | - |
| DPAttachmentspkg_dpattachments | 1 | High | 2026-09-10 | - |
| DPCasescom_dpcases | 1 | High | 2026-09-10 | - |
| DPCasespkg_dpcases | 1 | High | 2026-09-10 | - |
| DPMedialib_dpmedia | 1 | High | 2026-09-10 | - |
| DPMediapkg_dpmedia | 1 | High | 2026-09-10 | - |
| Easy Shopcom_easyshop | 1 | High | 2019-01-01 | CVE-2019-25760 |
| EasyDiscusscom_easydiscuss | 1 | High | 2026-01-16 | CVE-2026-21623CVE-2026-21624CVE-2026-21625CVE-2026-21626 |
| Event Gallerycom_eventgallery | 1 | High | 2026-09-26 | CVE-2026-97164CVE-2026-97165CVE-2026-100747CVE-2026-100748CVE-2026-100749 |
| Event Registration Pro Calendarcom_registrationpro | 1 | High | 2017-01-01 | CVE-2017-20273 |
| Extra Searchcom_extrasearch | 1 | High | 2017-01-01 | CVE-2017-20281 |
| Flip Wallcom_flipwall | 1 | High | 2026-06-19 | CVE-2017-20265 |
| Gurucom_guru | 1 | High | - | CVE-2022-23802 |
| HDW Playercom_hdwplayer | 1 | High | 2026-05-13 | CVE-2020-37218 |
| Ignite Gallerycom_igallery | 1 | High | 2026-07-07 | - |
| J-ClassifiedsManagercom_displayads | 1 | High | 2019-01-01 | CVE-2019-25751 |
| J-MultipleHotelReservationcom_jmultiplehotelreservation | 1 | High | 2019-01-01 | CVE-2019-25750 |
| jCartcom_jcart | 1 | High | 2017-01-01 | CVE-2017-20282 |
| JHotelReservationcom_jhotelreservation | 1 | High | 2019-01-01 | CVE-2019-25748 |
| jNewscom_jnews | 1 | High | 2020-03-09 | CVE-2015-7341CVE-2015-7342CVE-2015-7343 |
| Jomrescom_jomres | 1 | High | 2026-05-23 | CVE-2013-3931CVE-2013-3932CVE-2018-25354 |
| JoomCRMcom_joomcrm | 1 | High | 2019-01-01 | CVE-2019-25761 |
| Joomdlecom_joomdle | 1 | High | 2026-07-28 | CVE-2026-65881CVE-2026-65882 |
| LMS King Professionalcom_lmsking | 1 | High | 2017-01-01 | CVE-2017-20274 |
| miniOrange Custom APIcom_miniorange_customapi | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange Import Export Userscom_miniorange_importexportusers | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange Keycloak User Synccom_miniorange_keycloaksync | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange Restrict Files / Folderscom_miniorange_mediarestriction | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange SCIM User Provisioningcom_miniorange_scim | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange Two Factor Authenticationcom_miniorange_twofa | 1 | High | 2026-08-31 | CVE-2026-78074 |
| Modalspkg_modals | 1 | High | 2026-09-13 | CVE-2026-85189CVE-2026-88853 |
| Modules Anywherepkg_modulesanywhere | 1 | High | 2026-09-27 | CVE-2026-100750 |
| MyPortfoliocom_myportfolio | 1 | High | 2017-01-01 | CVE-2017-20280 |
| OS Propertycom_osproperty | 1 | High | 2026-08-09 | - |
| paGO Commercecom_pago | 1 | High | 2020-09-18 | CVE-2020-25751 |
| PHP-Bridgecom_phpbridge | 1 | High | 2017-01-01 | CVE-2017-20275 |
| Quantum Managercom_quantummanager | 1 | High | 2025-08-25 | CVE-2025-54300CVE-2025-54301 |
| Quick Indexpkg_quickindex | 1 | High | 2026-09-13 | CVE-2026-85190 |
| Regular Labs DB Replacercom_dbreplacer | 1 | High | 2026-07-22 | CVE-2026-63685CVE-2026-63265 |
| Regular Labs Extension Managercom_regularlabsmanager | 1 | High | 2026-07-22 | CVE-2026-64791CVE-2026-63265 |
| Regular Labs IP Loginiplogin | 1 | High | 2026-07-22 | CVE-2026-64797CVE-2026-64798CVE-2026-63265 |
| RO CSVIcom_csvi | 1 | High | 2026-07-28 | CVE-2026-65943CVE-2026-65944CVE-2026-65946 |
| S5 Registermod_s5_register | 1 | High | 2023-12-14 | CVE-2023-49707 |
| StreetGuessr Gamecom_streetguess | 1 | High | 2017-01-01 | CVE-2017-20271 |
| Survey Force Deluxecom_surveyforce | 1 | High | 2026-06-19 | CVE-2017-20256 |
| T4 Page Buildercom_t4pagebuilder | 1 | High | 2026-08-28 | CVE-2026-78374 |
| Twitch TVcom_twitchtv | 1 | High | 2017-01-01 | CVE-2017-20270 |
| Ultimate Property Listingcom_upl | 1 | High | 2017-01-01 | CVE-2017-20272 |
| vAccountcom_vaccount | 1 | High | 2019-01-01 | CVE-2019-25756 |
| vBizzcom_vbizz | 1 | High | 2019-01-01 | CVE-2019-25758CVE-2019-25759 |
| VMapcom_vmap | 1 | High | 2019-01-01 | CVE-2019-25753 |
| vReviewcom_vreview | 1 | High | 2019-01-01 | CVE-2019-25755 |
| vWishlistcom_vwishlist | 1 | High | 2019-01-01 | CVE-2019-25757 |
| Content Templatercom_contenttemplater | 5 | Medium | 2026-09-13 | CVE-2026-85188CVE-2026-63684CVE-2026-63280CVE-2026-63281CVE-2026-63683 |
| Advanced Module Manageradvancedmodules | 4 | Medium | 2026-09-13 | CVE-2026-85188CVE-2026-63280CVE-2026-63281CVE-2026-63683CVE-2026-63265 |
| ReReplacercom_rereplacer | 4 | Medium | 2026-09-13 | CVE-2026-85188CVE-2026-65754CVE-2026-63684CVE-2026-63280CVE-2026-63281 |
| JoomShoppingcom_jshopping | 2 | Medium, Low | 2026-07-22 | CVE-2026-63264CVE-2025-22211 |
| Phoca Mapscom_phocamaps | 2 | Medium | 2026-07-23 | CVE-2026-65763CVE-2026-23900 |
| Advanced Module Managerpkg_advancedmodules | 1 | Medium | 2026-09-13 | CVE-2026-85188 |
| All Video Sharecom_allvideoshare | 1 | Medium | 2026-08-28 | CVE-2026-78073 |
| Balbooa Gallerycom_bagallery | 1 | Medium | 2025-07-18 | CVE-2025-49486CVE-2023-23757 |
| Balbooa Gallerycom_gallery | 1 | Medium | 2026-08-18 | - |
| Booking - Book Itcom_booking | 1 | Medium | 2023-01-01 | CVE-2023-54357 |
| CCommentcom_comment | 1 | Medium | 2025-07-23 | CVE-2025-54297 |
| Clicky Analytics Dashboardmod_clicky_dash | 1 | Medium | 2023-12-14 | CVE-2023-40658 |
| Content Templaterpkg_contenttemplater | 1 | Medium | 2026-09-13 | CVE-2026-85188 |
| DJ-HelpfulArticlescom_djhelpfularticles | 1 | Medium | 2024-07-09 | CVE-2024-27183 |
| Easy Quick Contactmod_easyquickcontact | 1 | Medium | 2023-12-14 | CVE-2023-40659 |
| iProperty Real Estatecom_iproperty | 1 | Medium | 2026-04-09 | CVE-2023-54361 |
| JLex Reviewcom_jlexreview | 1 | Medium | 2026-04-09 | CVE-2023-54360 |
| JoomProjectcom_jpprojects | 1 | Medium | 2019-01-01 | CVE-2019-25762 |
| JS Jobscom_jsjobs | 1 | Medium | 2026-06-04 | CVE-2019-25740CVE-2018-25327CVE-2025-22206CVE-2025-22208CVE-2025-22209CVE-2025-49484CVE-2025-54475 |
| LivingWordcom_livingword | 1 | Medium | 2023-12-14 | CVE-2023-40627 |
| Membership Procom_osmembership | 1 | Medium | 2026-07-21 | CVE-2026-62415 |
| oneVotecom_onevote | 1 | Medium | 2023-07-11 | CVE-2023-23756 |
| osTicky2com_osticky2 | 1 | Medium | 2024-02-15 | CVE-2024-21728 |
| Phoca Guestbookcom_phocaguestbook | 1 | Medium | 2026-07-23 | CVE-2026-65762 |
| Regular Labs Better Frontend Linkmod_betterfrontendlink | 1 | Medium | 2026-07-22 | CVE-2026-63265 |
| Regular Labs CDNcdnforjoomla | 1 | Medium | 2026-07-22 | CVE-2026-65712CVE-2026-63265 |
| Regular Labs Email Protectoremailprotector | 1 | Medium | 2026-07-22 | CVE-2026-63265 |
| ReReplacerpkg_rereplacer | 1 | Medium | 2026-09-13 | CVE-2026-85188 |
| RSBlog!com_rsblog | 1 | Medium | 2025-01-01 | CVE-2025-50126CVE-2025-27754 |
| Solidrescom_solidres | 1 | Medium | 2026-04-09 | CVE-2023-54363 |
| Users Anywherepkg_usersanywhere | 1 | Medium | 2026-09-13 | CVE-2026-85196 |
| VirtueMartcom_virtuemart | 1 | Medium | 2026-04-09 | CVE-2023-54362CVE-2025-25228CVE-2025-55757 |
| XCloner Backupcom_xcloner-backupandrestore | 1 | Medium | 2020-05-23 | CVE-2020-13424 |
| HikaShopcom_hikashop | 1 | Low | 2026-07-20 | CVE-2026-61901CVE-2023-38044CVE-2024-40746CVE-2025-22210CVE-2025-25225CVE-2015-7344 |
| SEBLODcom_cck | 3 | Unrated | - | CVE-2026-66914 |
| Cache Cleanercachecleaner | 2 | Unrated | - | CVE-2026-64871CVE-2026-64872CVE-2026-64873CVE-2026-64874 |
| Cotton Cloudcom_cotton | 2 | Unrated | - | CVE-2026-67283CVE-2026-67284 |
| Admiror Gallerycom_admirorgallery | 1 | Unrated | - | CVE-2025-22205CVE-2023-38045 |
| Ajax Quizcom_ajaxquiz | 1 | Unrated | - | CVE-2017-20262 |
| Cache Cleanerpkg_cachecleaner | 1 | Unrated | - | CVE-2026-64871CVE-2026-64872CVE-2026-64873CVE-2026-64874 |
| CommentBoxcom_commentbox | 1 | Unrated | - | CVE-2025-54298 |
| Creative Gallerycom_creativegallery | 1 | Unrated | - | CVE-2023-23758 |
| DJ-Flyercom_djflyer | 1 | Unrated | - | CVE-2025-50127 |
| DJ-Reviewscom_djreviews | 1 | Unrated | - | CVE-2025-54295 |
| DOCmancom_docman | 1 | Unrated | - | CVE-2022-27910 |
| eXtplorercom_extplorer | 1 | Unrated | - | CVE-2023-40628 |
| FocalPointcom_focalpoint | 1 | Unrated | - | CVE-2017-20263 |
| iCagenda Calendar modulemod_icagenda_calendar | 1 | Unrated | - | CVE-2026-67365 |
| JCDashboardscom_jcdashboards | 1 | Unrated | - | CVE-2023-40630 |
| JMediacom_jmedia | 1 | Unrated | - | CVE-2026-60032CVE-2026-60033CVE-2026-60034 |
| JoomDOCcom_joomdoc | 1 | Unrated | - | CVE-2023-40657 |
| Joomla Quiz Deluxecom_joomlaquiz | 1 | Unrated | - | CVE-2017-20257 |
| JoomRecipecom_joomrecipe | 1 | Unrated | - | CVE-2017-20277CVE-2017-20278 |
| Keyboard Shortcutskeyboardshortcuts | 1 | Unrated | - | CVE-2026-65756 |
| Komentocom_komento | 1 | Unrated | - | CVE-2025-54294 |
| No Boss Calendarcom_nobosscalendar | 1 | Unrated | - | CVE-2025-49468 |
| No Boss Testimonialscom_nobosstestimonials | 1 | Unrated | - | CVE-2025-54299 |
| OSDownloadscom_osdownloads | 1 | Unrated | - | CVE-2017-20259 |
| Payagecom_payage | 1 | Unrated | - | CVE-2017-20279 |
| ProFilescom_profiles | 1 | Unrated | - | CVE-2025-54296 |
| Proforms Basiccom_proforms | 1 | Unrated | - | CVE-2023-34476CVE-2023-40655 |
| QuickFormcom_quickform | 1 | Unrated | - | CVE-2023-40656 |
| RSDirectory!com_rsdirectory | 1 | Unrated | - | CVE-2025-50058 |
| RSFirewall!com_rsfirewall | 1 | Unrated | - | CVE-2025-27445 |
| RSMail!com_rsmail | 1 | Unrated | - | CVE-2025-50056CVE-2025-30084 |
| RSMediaGallery!com_rsmediagallery | 1 | Unrated | - | CVE-2025-27753CVE-2025-32466 |
| RSTickets! Procom_rsticketspro | 1 | Unrated | - | CVE-2025-32465 |
| SIMGenealogycom_simgenealogy | 1 | Unrated | - | CVE-2017-20276 |
| SP Movie Databasecom_spmoviedb | 1 | Unrated | - | CVE-2017-20266 |
| Sponsor Wallcom_sponsorwall | 1 | Unrated | - | CVE-2017-20264 |
| Tooltipstooltips | 1 | Unrated | - | - |
| Zap Calendarcom_zcalendar | 1 | Unrated | - | CVE-2017-20268 |
No extension matches that.
Vulnerabilities we found and disclosed
90 write-ups. Every one was reported privately to the developer first.

14 More Joomla 3 Security Fixes, Each Tested on a Real 3.10.12 Site
Joomla 5.4.9 fixed 16 core issues. We backported every one reaching Joomla 3 to the mySites.guru one-click patch tool, each proved on a real 3.10.12 site.

SP Page Builder's Joomla 3 Security Patch Was Incomplete. Version 1.0.3 Fixes It.
JoomShaper's first Joomla 3 security patch for SP Page Builder left the captcha bypass live and the XSS fix incomplete. Version 1.0.3 closes both.

Phoca Cart 6.1.9 stops anyone downloading other customers' paid files
Phoca Cart before 6.1.9 let anonymous visitors download the digital products other customers bought. Only the Joomla 6 line is fixed, and 6.1.8 is affected.

Quix Page Builder 6.3.4 Fixes Guest Access and Editor Code Execution Flaws
Quix Page Builder 6.3.4 stops guests changing Quix settings or reading restricted pages, and editors running code on the server. Update every Joomla site.

AcyMailing Shoots Itself in the Foot With a Vanishing Update Site
AcyMailing adds its Joomla update site from PHP, not its manifest, so Rebuild deletes it and Joomla calls a site on a vulnerable version up to date.

OS CCK 8.3.16 for Joomla Fixes a No-Login PHP Upload and an SQL Injection, but the Updater Still Offers 8.3.14
OS CCK for Joomla before 8.3.16 let anyone upload and run PHP (CVE-2026-102427, CVSS 10.0) and had a no-login SQL injection. The updater won't offer the fix.

JCTables for Joomla: Unauthenticated SQL Injection Fixed in 1.21.1
CVE-2026-76570 lets anyone read and rewrite a Joomla database through the JCTables extension without logging in. Scored 10.0 Critical, fixed in 1.21.1.

Joomla 5.4.9 and 6.1.4 Fix 16 Security Issues, Two Rated High
Joomla 5.4.9 and 6.1.4 fix 16 core security issues, including cache directory deletion, SSRF, an MFA bypass and account creation with registration switched off.

Balbooa Forms 2.4.3.4 Fixes Five Security Issues
Balbooa Forms 2.4.3.4 fixes five CVEs in the Joomla form builder, led by a 9.5 unauthenticated RCE. Every version below 2.4.3.4 is affected. Update now.

Three OrdaSoft Joomla Extensions Have Unauthenticated SQL Injections in Their Sort Order
Real Estate Manager, Vehicle Manager and Book Library for Joomla each have an SQL injection needing no login and a reflected XSS. Six CVEs and their fixes.

Modules Anywhere 10.0.0 and Tabs & Accordions 3.2.0 Close Two Content Author Security Holes
CVE-2026-100750 and CVE-2026-100751: Regular Labs fixed two High severity issues in Modules Anywhere 10.0.0 and Tabs & Accordions 3.2.0 for Joomla.

UP 6.1.0 fixes file read and code execution in the UP plugin for Joomla
Before UP 6.1.0, one anonymous request could read a Joomla site's configuration.php through the UP plugin, and any author could run PHP. We found it.