Joomla Vulnerability Database
These are the 301 vulnerability rules mySites.guru checks every connected Joomla site against, covering 192 extensions and 367 CVE-numbered vulnerabilities. A good number of them exist because we found the flaw ourselves and reported it to the developer before publishing.
Rules current as of 13 September 2026. Subscribers see which of their own sites are affected, on the site's Manage page.
Why no WordPress CVE or vulnerability data?
WordPress is covered by the service too: mySites.guru integrates Wordfence's vulnerability feed in full, mirroring the data published on Wordfence's vulnerability pages, and every connected WordPress site is checked against it on each audit. To research a WordPress plugin or theme yourself, search Wordfence's database directly.
Subscribe by RSS
New rules as we start checking sites against them. One item per rule, so a CVE needing a rule per Joomla branch appears once for each.
https://mysites.guru/vulnerabilities/rss.xml This page is public. Acting on it across a portfolio is the mySites.guru subscription: each audit checks every connected Joomla and WordPress site against these rules, flags the ones running an affected version, and updates the extension in one click across all of them. One price, unlimited sites, 90,000+ sites protected in 14 years.
Extensions we track
Filter by severity, or search for the extension or CVE you're after. Browse every tracked CVE at the Joomla CVE index.
| Extension | Rules | Severity | Latest | CVEs |
|---|---|---|---|---|
| Page Builder CKcom_pagebuilderck | 10 | Critical, High, Medium | 2026-08-17 | CVE-2026-74254CVE-2026-77993CVE-2026-77994CVE-2026-63048CVE-2026-62414CVE-2026-56290 |
| J2Store / J2Commercecom_j2store | 6 | Critical, High | 2026-08-31 | CVE-2026-77999CVE-2026-78000CVE-2026-78064CVE-2026-78065CVE-2026-78069CVE-2026-67358CVE-2026-67359CVE-2026-67360CVE-2026-67361CVE-2026-67362CVE-2026-74252CVE-2020-13996 |
| miniOrange SAML SSOcom_miniorange_saml | 6 | Critical, High | 2026-08-31 | CVE-2026-78074CVE-2026-77998 |
| Phoca Cartcom_phocacart | 6 | Critical, Medium | - | CVE-2026-74251CVE-2026-76564CVE-2026-76565 |
| Phoca Downloadcom_phocadownload | 6 | Critical, High, Medium | 2026-07-10 | CVE-2026-57828CVE-2026-76569 |
| miniOrange OAuth Clientcom_miniorange_oauth | 4 | Critical, High | 2026-08-31 | CVE-2026-78074CVE-2026-77995 |
| Articles Anywherearticlesanywhere | 3 | Critical, High | 2026-09-13 | CVE-2026-85195CVE-2026-85196CVE-2026-64793CVE-2026-64794CVE-2026-64795CVE-2026-64799CVE-2026-65755 |
| Events Bookingcom_eventbooking | 3 | Critical, Medium | 2026-07-20 | CVE-2026-63047CVE-2026-58149CVE-2026-60024CVE-2026-60025 |
| Helix Ultimateshaper_helixultimate | 3 | Critical, High | 2026-08-31 | CVE-2026-78075CVE-2026-78076CVE-2026-78077CVE-2026-78078CVE-2026-78079CVE-2026-57829CVE-2026-57830 |
| Helix Ultimate Frameworkhelixultimate | 3 | Critical, High | 2026-08-31 | CVE-2026-78075CVE-2026-78076CVE-2026-78077CVE-2026-78078CVE-2026-78079CVE-2026-57829CVE-2026-57830 |
| iCagendacom_icagenda | 3 | Critical | 2026-06-15 | CVE-2026-48939CVE-2026-67365CVE-2026-71571CVE-2026-67366CVE-2026-71570 |
| J-BusinessDirectorycom_jbusinessdirectory | 3 | Critical | 2026-08-19 | CVE-2026-75949CVE-2026-75954CVE-2026-75956CVE-2026-75950CVE-2026-75951CVE-2026-75952CVE-2026-75953CVE-2026-75955CVE-2020-5182CVE-2019-25752 |
| JCEcom_jce | 3 | Critical, High, Medium | 2026-07-29 | CVE-2026-65891CVE-2026-48907CVE-2015-7339 |
| Sourcerersourcerer | 3 | Critical, Low | 2026-08-17 | CVE-2026-74253CVE-2025-22204CVE-2026-64796 |
| SP Page Buildercom_sppagebuilder | 3 | Critical | 2026-07-27 | CVE-2026-65876CVE-2026-65766CVE-2026-65877CVE-2026-66494CVE-2026-65878CVE-2026-65879CVE-2026-48908CVE-2026-67285CVE-2026-67286CVE-2026-67287 |
| ZOOcom_zoo | 3 | Critical, High, Medium | 2026-08-21 | CVE-2026-76611CVE-2026-76612CVE-2026-77028CVE-2026-77029CVE-2026-76610CVE-2026-74803CVE-2026-74804CVE-2026-75114 |
| Balbooa Formscom_baforms | 2 | Critical | 2026-08-18 | CVE-2026-67364CVE-2026-67363CVE-2026-65880CVE-2026-56291CVE-2025-49485 |
| Easy Folder Listing Procom_easyfolderlistingpro | 2 | Critical | 2024-11-26 | CVE-2024-11145 |
| Fabrikcom_fabrik | 2 | Critical, High | 2026-08-22 | CVE-2026-76571CVE-2026-76596CVE-2026-76597CVE-2026-76598CVE-2026-76600CVE-2026-76601CVE-2026-76602CVE-2026-76603CVE-2026-76604CVE-2026-76605CVE-2026-76606CVE-2026-76607CVE-2026-76608CVE-2026-76609CVE-2026-77027CVE-2026-77992CVE-2026-76599CVE-2020-37219CVE-2026-67282CVE-2026-66915 |
| Gridboxcom_gridbox | 2 | Critical | 2026-08-10 | CVE-2026-61425CVE-2026-65884CVE-2026-65885CVE-2026-65889CVE-2026-65890CVE-2026-66488CVE-2026-66489CVE-2026-66490CVE-2026-65886CVE-2026-65887CVE-2026-65888CVE-2026-65947 |
| jDownloadscom_jdownloads | 2 | Critical, Medium | 2026-07-17 | CVE-2026-61900CVE-2025-55758CVE-2022-27909 |
| JEventscom_jevents | 2 | Critical | 2025-01-01 | CVE-2025-49467CVE-2015-7340 |
| K2com_k2 | 2 | Critical, Medium | 2026-06-25 | CVE-2026-48941CVE-2026-48942CVE-2026-48943CVE-2026-48944CVE-2026-48945CVE-2026-48946CVE-2026-48940 |
| Smart Slider 3 Prosmartslider3 | 2 | Critical, Medium | 2026-04-08 | CVE-2026-34424 |
| AcyMailingcom_acym | 1 | Critical | 2026-07-09 | CVE-2026-56292CVE-2023-39970CVE-2023-39971CVE-2023-39972CVE-2023-39973CVE-2023-39974 |
| Aimy Captcha-Less Form Guardaimycaptchalessformguard | 1 | Critical | 2026-07-28 | CVE-2026-65883 |
| Articles Calendarmod_articles_calendar | 1 | Critical | 2025-07-18 | CVE-2025-26855 |
| Articles Calendararticlescalendar | 1 | Critical | 2025-07-18 | CVE-2025-26855 |
| Astroid Frameworkastroid | 1 | Critical | 2026-03-05 | CVE-2026-21628 |
| BrainCert Virtual Classroomcom_virtualclassroom | 1 | Critical | 2023-08-07 | CVE-2023-34477 |
| Creative Contact Formcom_creativecontactform | 1 | Critical | 2020-03-04 | CVE-2014-8739CVE-2020-9364 |
| DJ-Classifiedscom_djclassifieds | 1 | Critical | 2026-07-20 | CVE-2026-61424CVE-2025-54474 |
| EDocmancom_edocman | 1 | Critical | 2026-07-14 | CVE-2026-57832 |
| Helix3 Templateshaper_helix3 | 1 | Critical | 2026-06-29 | CVE-2026-49049 |
| JEM - Joomla Event Managercom_jem | 1 | Critical | 2026-08-27 | CVE-2026-77034CVE-2026-77035CVE-2026-77989CVE-2026-77990CVE-2026-77991 |
| JooDatabasecom_joodb | 1 | Critical | 2026-09-03 | CVE-2026-78080 |
| JoomCCKcom_joomcck | 1 | Critical | 2026-07-17 | CVE-2026-49048 |
| LMS Litecom_lmslite | 1 | Critical | 2023-12-14 | CVE-2023-40629 |
| Modules Anywheremodulesanywhere | 1 | Critical | 2026-07-22 | CVE-2026-65757CVE-2026-64793CVE-2026-64795 |
| Regular Labs GeoIPgeoip | 1 | Critical | 2026-07-23 | CVE-2026-65431CVE-2026-64876CVE-2026-65430CVE-2026-64875 |
| RSFiles!com_rsfiles | 1 | Critical | 2026-07-10 | CVE-2026-57827CVE-2025-50057 |
| RSForm!Procom_rsform | 1 | Critical | 2025-01-01 | CVE-2025-30085CVE-2025-27444 |
| SP LMScom_splms | 1 | Critical | 2026-01-01 | CVE-2026-48909 |
| SP Property Findercom_spproperty | 1 | Critical | 2026-09-10 | CVE-2026-78082CVE-2026-78303CVE-2026-78083CVE-2026-78084CVE-2026-78302CVE-2026-78085 |
| Starshopcom_starshop | 1 | Critical | 2023-12-14 | CVE-2023-49708 |
| Visitors Countermod_vvisit_counter | 1 | Critical | 2025-10-03 | CVE-2025-40636 |
| DPCalendarcom_dpcalendar | 7 | High, Medium | 2026-08-28 | CVE-2026-78071CVE-2026-78070CVE-2026-57831CVE-2024-21727 |
| YOOtheme Proyootheme | 6 | High, Medium | 2026-08-25 | CVE-2026-77997CVE-2026-76613CVE-2026-75115 |
| Convert Formscom_convertforms | 5 | High | 2026-07-23 | CVE-2026-65758CVE-2024-40744CVE-2024-40745CVE-2025-22212CVE-2026-77026 |
| Visformscom_visforms | 4 | High | - | CVE-2023-23753 |
| Conditional Contentconditionalcontent | 3 | High, Medium | 2026-09-13 | CVE-2026-85192CVE-2026-85188CVE-2026-63280CVE-2026-63281CVE-2026-63683CVE-2026-64792 |
| Modalsmodals | 3 | High | 2026-09-13 | CVE-2026-85189CVE-2026-88853CVE-2026-65713 |
| miniOrange LDAP Integrationcom_miniorange_dirsync | 2 | High | 2026-08-31 | CVE-2026-78074CVE-2023-23749 |
| Phoca Commandercom_phocacommander | 2 | High | 2026-07-27 | CVE-2026-65764CVE-2026-65765CVE-2025-54473CVE-2026-66491CVE-2026-66492CVE-2026-66493 |
| Sexy Polling Reloadedcom_sexypolling | 2 | High | 2026-08-28 | CVE-2026-78072 |
| Users Anywhereusersanywhere | 2 | High | 2026-09-13 | CVE-2026-85196CVE-2026-64794CVE-2026-64795CVE-2026-64799CVE-2026-65755 |
| YOOtheme Prolocation | 2 | High | 2026-08-25 | CVE-2026-77996 |
| 4Analyticscom_foranalytics | 1 | High | 2026-07-15 | CVE-2026-58077CVE-2026-57833 |
| AcyMailingcom_acymailing | 1 | High | 2020-03-09 | CVE-2015-7338 |
| Admiror Framesadmirorframes | 1 | High | 2024-06-28 | CVE-2024-5735CVE-2024-5736CVE-2024-5737 |
| Articles Anywherepkg_articlesanywhere | 1 | High | 2026-09-13 | CVE-2026-85195CVE-2026-85196 |
| ChronoForms 8com_chronoforms8 | 1 | High | 2026-07-17 | CVE-2026-58148 |
| Conditional Contentpkg_conditionalcontent | 1 | High | 2026-09-13 | CVE-2026-85192CVE-2026-85188 |
| DPAttachmentscom_dpattachments | 1 | High | 2026-09-10 | - |
| DPAttachmentspkg_dpattachments | 1 | High | 2026-09-10 | - |
| DPCasescom_dpcases | 1 | High | 2026-09-10 | - |
| DPCasespkg_dpcases | 1 | High | 2026-09-10 | - |
| DPMedialib_dpmedia | 1 | High | 2026-09-10 | - |
| DPMediapkg_dpmedia | 1 | High | 2026-09-10 | - |
| Easy Shopcom_easyshop | 1 | High | 2019-01-01 | CVE-2019-25760 |
| EasyDiscusscom_easydiscuss | 1 | High | 2026-01-16 | CVE-2026-21623CVE-2026-21624CVE-2026-21625CVE-2026-21626 |
| EasyStorecom_easystore | 1 | High | - | CVE-2026-65759CVE-2026-65760CVE-2026-65761 |
| Event Registration Pro Calendarcom_registrationpro | 1 | High | 2017-01-01 | CVE-2017-20273 |
| Extra Searchcom_extrasearch | 1 | High | 2017-01-01 | CVE-2017-20281 |
| Flip Wallcom_flipwall | 1 | High | 2026-06-19 | CVE-2017-20265 |
| HDW Playercom_hdwplayer | 1 | High | 2026-05-13 | CVE-2020-37218 |
| Ignite Gallerycom_igallery | 1 | High | 2026-07-07 | - |
| J-ClassifiedsManagercom_displayads | 1 | High | 2019-01-01 | CVE-2019-25751 |
| J-MultipleHotelReservationcom_jmultiplehotelreservation | 1 | High | 2019-01-01 | CVE-2019-25750 |
| jCartcom_jcart | 1 | High | 2017-01-01 | CVE-2017-20282 |
| JHotelReservationcom_jhotelreservation | 1 | High | 2019-01-01 | CVE-2019-25748 |
| jNewscom_jnews | 1 | High | 2020-03-09 | CVE-2015-7341CVE-2015-7342CVE-2015-7343 |
| Jomrescom_jomres | 1 | High | 2026-05-23 | CVE-2013-3931CVE-2013-3932CVE-2018-25354 |
| JoomCRMcom_joomcrm | 1 | High | 2019-01-01 | CVE-2019-25761 |
| Joomdlecom_joomdle | 1 | High | 2026-07-28 | CVE-2026-65881CVE-2026-65882 |
| JoomGallerycom_joomgallery | 1 | High | 2026-08-22 | CVE-2026-66917CVE-2026-66916 |
| LMS King Professionalcom_lmsking | 1 | High | 2017-01-01 | CVE-2017-20274 |
| miniOrange Custom APIcom_miniorange_customapi | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange Import Export Userscom_miniorange_importexportusers | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange Keycloak User Synccom_miniorange_keycloaksync | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange Restrict Files / Folderscom_miniorange_mediarestriction | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange SCIM User Provisioningcom_miniorange_scim | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange Two Factor Authenticationcom_miniorange_twofa | 1 | High | 2026-08-31 | CVE-2026-78074 |
| Modalspkg_modals | 1 | High | 2026-09-13 | CVE-2026-85189CVE-2026-88853 |
| MyPortfoliocom_myportfolio | 1 | High | 2017-01-01 | CVE-2017-20280 |
| paGO Commercecom_pago | 1 | High | 2020-09-18 | CVE-2020-25751 |
| PHP-Bridgecom_phpbridge | 1 | High | 2017-01-01 | CVE-2017-20275 |
| Quantum Managercom_quantummanager | 1 | High | 2025-08-25 | CVE-2025-54300CVE-2025-54301 |
| Quix Page Buildercom_quix | 1 | High | 2026-07-15 | CVE-2026-58078CVE-2026-60026CVE-2026-60027CVE-2026-60028CVE-2026-60029CVE-2026-60030CVE-2026-60031 |
| Regular Labs DB Replacercom_dbreplacer | 1 | High | 2026-07-22 | CVE-2026-63685CVE-2026-63265 |
| Regular Labs Extension Managercom_regularlabsmanager | 1 | High | 2026-07-22 | CVE-2026-64791CVE-2026-63265 |
| Regular Labs IP Loginiplogin | 1 | High | 2026-07-22 | CVE-2026-64797CVE-2026-64798CVE-2026-63265 |
| RO CSVIcom_csvi | 1 | High | 2026-07-28 | CVE-2026-65943CVE-2026-65944CVE-2026-65946 |
| S5 Registermod_s5_register | 1 | High | 2023-12-14 | CVE-2023-49707 |
| StreetGuessr Gamecom_streetguess | 1 | High | 2017-01-01 | CVE-2017-20271 |
| Survey Force Deluxecom_surveyforce | 1 | High | 2026-06-19 | CVE-2017-20256 |
| T4 Page Buildercom_t4pagebuilder | 1 | High | 2026-08-28 | CVE-2026-78374 |
| Twitch TVcom_twitchtv | 1 | High | 2017-01-01 | CVE-2017-20270 |
| Ultimate Property Listingcom_upl | 1 | High | 2017-01-01 | CVE-2017-20272 |
| Users Anywherepkg_usersanywhere | 1 | High | 2026-09-13 | CVE-2026-85196 |
| vAccountcom_vaccount | 1 | High | 2019-01-01 | CVE-2019-25756 |
| vBizzcom_vbizz | 1 | High | 2019-01-01 | CVE-2019-25758CVE-2019-25759 |
| VMapcom_vmap | 1 | High | 2019-01-01 | CVE-2019-25753 |
| vReviewcom_vreview | 1 | High | 2019-01-01 | CVE-2019-25755 |
| vWishlistcom_vwishlist | 1 | High | 2019-01-01 | CVE-2019-25757 |
| Content Templatercom_contenttemplater | 5 | Medium | 2026-09-13 | CVE-2026-85188CVE-2026-63684CVE-2026-63280CVE-2026-63281CVE-2026-63683 |
| Snippetscom_snippets | 5 | Medium | 2026-09-13 | CVE-2026-88852CVE-2026-63684CVE-2026-64792CVE-2026-63265 |
| Advanced Module Manageradvancedmodules | 4 | Medium | 2026-09-13 | CVE-2026-85188CVE-2026-63280CVE-2026-63281CVE-2026-63683CVE-2026-63265 |
| ReReplacercom_rereplacer | 4 | Medium | 2026-09-13 | CVE-2026-85188CVE-2026-65754CVE-2026-63684CVE-2026-63280CVE-2026-63281 |
| Tabs & Accordionstabsaccordions | 3 | Medium | 2026-09-13 | CVE-2026-85191CVE-2026-64792CVE-2026-63265 |
| JoomShoppingcom_jshopping | 2 | Medium, Low | 2026-07-22 | CVE-2026-63264CVE-2025-22211 |
| Phoca Mapscom_phocamaps | 2 | Medium | 2026-07-23 | CVE-2026-65763CVE-2026-23900 |
| Quick Indexquickindex | 2 | Medium | 2026-09-13 | CVE-2026-85190CVE-2026-63265 |
| Advanced Module Managerpkg_advancedmodules | 1 | Medium | 2026-09-13 | CVE-2026-85188 |
| All Video Sharecom_allvideoshare | 1 | Medium | 2026-08-28 | CVE-2026-78073 |
| Balbooa Gallerycom_bagallery | 1 | Medium | 2025-07-18 | CVE-2025-49486CVE-2023-23757 |
| Balbooa Gallerycom_gallery | 1 | Medium | 2026-08-18 | - |
| Booking - Book Itcom_booking | 1 | Medium | 2023-01-01 | CVE-2023-54357 |
| CCommentcom_comment | 1 | Medium | 2025-07-23 | CVE-2025-54297 |
| Clicky Analytics Dashboardmod_clicky_dash | 1 | Medium | 2023-12-14 | CVE-2023-40658 |
| Content Templaterpkg_contenttemplater | 1 | Medium | 2026-09-13 | CVE-2026-85188 |
| DJ-HelpfulArticlescom_djhelpfularticles | 1 | Medium | 2024-07-09 | CVE-2024-27183 |
| Easy Quick Contactmod_easyquickcontact | 1 | Medium | 2023-12-14 | CVE-2023-40659 |
| iProperty Real Estatecom_iproperty | 1 | Medium | 2026-04-09 | CVE-2023-54361 |
| JLex Reviewcom_jlexreview | 1 | Medium | 2026-04-09 | CVE-2023-54360 |
| JoomProjectcom_jpprojects | 1 | Medium | 2019-01-01 | CVE-2019-25762 |
| JS Jobscom_jsjobs | 1 | Medium | 2026-06-04 | CVE-2019-25740CVE-2018-25327CVE-2025-22206CVE-2025-22208CVE-2025-22209CVE-2025-49484CVE-2025-54475 |
| LivingWordcom_livingword | 1 | Medium | 2023-12-14 | CVE-2023-40627 |
| Membership Procom_osmembership | 1 | Medium | 2026-07-21 | CVE-2026-62415 |
| oneVotecom_onevote | 1 | Medium | 2023-07-11 | CVE-2023-23756 |
| osTicky2com_osticky2 | 1 | Medium | 2024-02-15 | CVE-2024-21728 |
| Phoca Guestbookcom_phocaguestbook | 1 | Medium | 2026-07-23 | CVE-2026-65762 |
| Quick Indexpkg_quickindex | 1 | Medium | 2026-09-13 | CVE-2026-85190 |
| Regular Labs Better Frontend Linkmod_betterfrontendlink | 1 | Medium | 2026-07-22 | CVE-2026-63265 |
| Regular Labs CDNcdnforjoomla | 1 | Medium | 2026-07-22 | CVE-2026-65712CVE-2026-63265 |
| Regular Labs Email Protectoremailprotector | 1 | Medium | 2026-07-22 | CVE-2026-63265 |
| ReReplacerpkg_rereplacer | 1 | Medium | 2026-09-13 | CVE-2026-85188 |
| RSBlog!com_rsblog | 1 | Medium | 2025-01-01 | CVE-2025-50126CVE-2025-27754 |
| Snippetspkg_snippets | 1 | Medium | 2026-09-13 | CVE-2026-88852 |
| Solidrescom_solidres | 1 | Medium | 2026-04-09 | CVE-2023-54363 |
| Tabs & Accordionspkg_tabsaccordions | 1 | Medium | 2026-09-13 | CVE-2026-85191 |
| VirtueMartcom_virtuemart | 1 | Medium | 2026-04-09 | CVE-2023-54362CVE-2025-25228CVE-2025-55757 |
| XCloner Backupcom_xcloner-backupandrestore | 1 | Medium | 2020-05-23 | CVE-2020-13424 |
| HikaShopcom_hikashop | 1 | Low | 2026-07-20 | CVE-2026-61901CVE-2023-38044CVE-2024-40746CVE-2025-22210CVE-2025-25225CVE-2015-7344 |
| SEBLODcom_cck | 3 | Unrated | - | CVE-2026-66914 |
| Cotton Cloudcom_cotton | 2 | Unrated | - | CVE-2026-67283CVE-2026-67284 |
| Admiror Gallerycom_admirorgallery | 1 | Unrated | - | CVE-2025-22205CVE-2023-38045 |
| Ajax Quizcom_ajaxquiz | 1 | Unrated | - | CVE-2017-20262 |
| Cache Cleanercachecleaner | 1 | Unrated | - | CVE-2026-64871CVE-2026-64872CVE-2026-64873CVE-2026-64874 |
| CommentBoxcom_commentbox | 1 | Unrated | - | CVE-2025-54298 |
| Creative Gallerycom_creativegallery | 1 | Unrated | - | CVE-2023-23758 |
| DJ-Flyercom_djflyer | 1 | Unrated | - | CVE-2025-50127 |
| DJ-Reviewscom_djreviews | 1 | Unrated | - | CVE-2025-54295 |
| DOCmancom_docman | 1 | Unrated | - | CVE-2022-27910 |
| eXtplorercom_extplorer | 1 | Unrated | - | CVE-2023-40628 |
| FocalPointcom_focalpoint | 1 | Unrated | - | CVE-2017-20263 |
| Gurucom_guru | 1 | Unrated | - | CVE-2022-23802 |
| iCagenda Calendar modulemod_icagenda_calendar | 1 | Unrated | - | CVE-2026-67365 |
| JCDashboardscom_jcdashboards | 1 | Unrated | - | CVE-2023-40630 |
| JMediacom_jmedia | 1 | Unrated | - | CVE-2026-60032CVE-2026-60033CVE-2026-60034 |
| JoomDOCcom_joomdoc | 1 | Unrated | - | CVE-2023-40657 |
| Joomla Quiz Deluxecom_joomlaquiz | 1 | Unrated | - | CVE-2017-20257 |
| JoomRecipecom_joomrecipe | 1 | Unrated | - | CVE-2017-20277CVE-2017-20278 |
| Keyboard Shortcutskeyboardshortcuts | 1 | Unrated | - | CVE-2026-65756 |
| Komentocom_komento | 1 | Unrated | - | CVE-2025-54294 |
| No Boss Calendarcom_nobosscalendar | 1 | Unrated | - | CVE-2025-49468 |
| No Boss Testimonialscom_nobosstestimonials | 1 | Unrated | - | CVE-2025-54299 |
| OSDownloadscom_osdownloads | 1 | Unrated | - | CVE-2017-20259 |
| Payagecom_payage | 1 | Unrated | - | CVE-2017-20279 |
| ProFilescom_profiles | 1 | Unrated | - | CVE-2025-54296 |
| Proforms Basiccom_proforms | 1 | Unrated | - | CVE-2023-34476CVE-2023-40655 |
| QuickFormcom_quickform | 1 | Unrated | - | CVE-2023-40656 |
| RSDirectory!com_rsdirectory | 1 | Unrated | - | CVE-2025-50058 |
| RSFirewall!com_rsfirewall | 1 | Unrated | - | CVE-2025-27445 |
| RSMail!com_rsmail | 1 | Unrated | - | CVE-2025-50056CVE-2025-30084 |
| RSMediaGallery!com_rsmediagallery | 1 | Unrated | - | CVE-2025-27753CVE-2025-32466 |
| RSTickets! Procom_rsticketspro | 1 | Unrated | - | CVE-2025-32465 |
| SIMGenealogycom_simgenealogy | 1 | Unrated | - | CVE-2017-20276 |
| SP Movie Databasecom_spmoviedb | 1 | Unrated | - | CVE-2017-20266 |
| Sponsor Wallcom_sponsorwall | 1 | Unrated | - | CVE-2017-20264 |
| Tooltipstooltips | 1 | Unrated | - | - |
| Zap Calendarcom_zcalendar | 1 | Unrated | - | CVE-2017-20268 |
No extension matches that.
Vulnerabilities we found and disclosed
69 write-ups. Every one was reported privately to the developer first.

Regular Labs Publishes 24 Joomla Extension Updates Including 10 Security Fixes
Regular Labs shipped 24 Joomla extension updates on 13 September 2026. Ten fix security issues across nine CVEs, and four change behaviour on update.

Unauthenticated SQL Injection in SP Property Finder found by mySites.guru
mySites.guru found an unauthenticated blind SQL injection in JoomShaper's SP Property Finder. Any visitor could read the database. Fixed in 4.1.4.

Digital Peak patches four Joomla extensions after a Claude audit
Digital Peak shipped out-of-band fixes for DPCalendar, DPMedia, DPAttachments and DPCases on 10 September. DPAttachments is the one to do first.

T4 Page Builder 2.3.0 Fixes an Unauthenticated Mail Relay
JoomlArt's T4 Page Builder 2.3.0 closes an unauthenticated open mail relay we reported in August. A week on, five in six installs we see are still older.

J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws we reported
J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws mySites.guru reported, including anonymous PayPal order confirmation and a 9.5 backend escalation.

DPCalendar 10.12.0 fixes an SQL injection and an XSS
Digital Peak fixed a blind SQL injection and a stored XSS in DPCalendar 10.12.0, backported to 8.19.5 for Joomla 3. Both need a logged-in user.

Helix Ultimate 2.2.10 Fixes Twelve Security Issues, Including a Pre-Login Bypass
Helix Ultimate 2.2.10 is a security release for the Joomla template framework. Every version below it is affected. Here is what it fixes and how to update.

Helix Ultimate's Third Joomla 3 Patch Since JoomShaper Said There Would Be None
JoomShaper said its Joomla 3 products would get no security patches regardless of severity. The Helix Ultimate template framework has now had four.

Three CVEs in miniOrange Extensions for Joomla, All Now Fixed
Two CVSS 10.0 authentication bypasses and a remote uninstall flaw naming 23 extensions. Every affected free edition now has a fixed version, released 31 August.

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes
Fabrik 4.7.2 for the Joomla extension closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Update now.

Five Security Issues in JEM (Joomla Event Manager), and No Stable Fix Yet
mySites.guru found and reported multiple security issues in JEM (Joomla Event Manager), including an unauthenticated article overwrite. No stable fix yet.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66
YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.