Joomla Vulnerability Database
These are the 261 vulnerability rules mySites.guru checks every connected Joomla site against, covering 176 extensions and 351 CVE-numbered vulnerabilities. A good number of them exist because we found the flaw ourselves and reported it to the developer before publishing.
Rules current as of 8 September 2026. Subscribers see which of their own sites are affected, on the site's Manage page.
Why no WordPress CVE or vulnerability data?
WordPress is covered by the service too: mySites.guru integrates Wordfence's vulnerability feed in full, mirroring the data published on Wordfence's vulnerability pages, and every connected WordPress site is checked against it on each audit. To research a WordPress plugin or theme yourself, search Wordfence's database directly.
Subscribe by RSS
New rules as we start checking sites against them. One item per rule, so a CVE needing a rule per Joomla branch appears once for each.
https://mysites.guru/vulnerabilities/rss.xml This page is public. Acting on it across a portfolio is the mySites.guru subscription: each audit checks every connected Joomla and WordPress site against these rules, flags the ones running an affected version, and updates the extension in one click across all of them. One price, unlimited sites, 90,000+ sites protected in 14 years.
Extensions we track
Filter by severity, or search for the extension or CVE you're after. Browse every tracked CVE at the Joomla CVE index.
| Extension | Rules | Severity | Latest | CVEs |
|---|---|---|---|---|
| Page Builder CKcom_pagebuilderck | 10 | Critical, High, Medium | 2026-08-17 | CVE-2026-74254CVE-2026-77993CVE-2026-77994CVE-2026-63048CVE-2026-62414CVE-2026-56290 |
| J2Store / J2Commercecom_j2store | 6 | Critical, High | 2026-08-31 | CVE-2026-77999CVE-2026-78000CVE-2026-78064CVE-2026-78065CVE-2026-78069CVE-2026-67358CVE-2026-67359CVE-2026-67360CVE-2026-67361CVE-2026-67362CVE-2026-74252CVE-2020-13996 |
| miniOrange SAML SSOcom_miniorange_saml | 6 | Critical, High | 2026-08-31 | CVE-2026-78074CVE-2026-77998 |
| Phoca Cartcom_phocacart | 6 | Critical, Medium | - | CVE-2026-74251CVE-2026-76564CVE-2026-76565 |
| Phoca Downloadcom_phocadownload | 6 | Critical, High, Medium | 2026-07-10 | CVE-2026-57828CVE-2026-76569 |
| miniOrange OAuth Clientcom_miniorange_oauth | 4 | Critical, High | 2026-08-31 | CVE-2026-78074CVE-2026-77995 |
| Events Bookingcom_eventbooking | 3 | Critical, Medium | 2026-07-20 | CVE-2026-63047CVE-2026-58149CVE-2026-60024CVE-2026-60025 |
| Helix Ultimateshaper_helixultimate | 3 | Critical, High | 2026-08-31 | CVE-2026-78075CVE-2026-78076CVE-2026-78077CVE-2026-78078CVE-2026-78079CVE-2026-57829CVE-2026-57830 |
| Helix Ultimate Frameworkhelixultimate | 3 | Critical, High | 2026-08-31 | CVE-2026-78075CVE-2026-78076CVE-2026-78077CVE-2026-78078CVE-2026-78079CVE-2026-57829CVE-2026-57830 |
| iCagendacom_icagenda | 3 | Critical | 2026-06-15 | CVE-2026-48939CVE-2026-67365CVE-2026-71571CVE-2026-67366CVE-2026-71570 |
| J-BusinessDirectorycom_jbusinessdirectory | 3 | Critical | 2026-08-19 | CVE-2026-75949CVE-2026-75954CVE-2026-75956CVE-2026-75950CVE-2026-75951CVE-2026-75952CVE-2026-75953CVE-2026-75955CVE-2020-5182CVE-2019-25752 |
| JCEcom_jce | 3 | Critical, High, Medium | 2026-07-29 | CVE-2026-65891CVE-2026-48907CVE-2015-7339 |
| Sourcerersourcerer | 3 | Critical, Low | 2026-08-17 | CVE-2026-74253CVE-2025-22204CVE-2026-64796 |
| SP Page Buildercom_sppagebuilder | 3 | Critical | 2026-07-27 | CVE-2026-65876CVE-2026-65766CVE-2026-65877CVE-2026-66494CVE-2026-65878CVE-2026-65879CVE-2026-48908CVE-2026-67285CVE-2026-67286CVE-2026-67287 |
| ZOOcom_zoo | 3 | Critical, High, Medium | 2026-08-21 | CVE-2026-76611CVE-2026-76612CVE-2026-77028CVE-2026-77029CVE-2026-76610CVE-2026-74803CVE-2026-74804CVE-2026-75114 |
| Balbooa Formscom_baforms | 2 | Critical | 2026-08-18 | CVE-2026-67364CVE-2026-67363CVE-2026-65880CVE-2026-56291CVE-2025-49485 |
| Easy Folder Listing Procom_easyfolderlistingpro | 2 | Critical | 2024-11-26 | CVE-2024-11145 |
| Fabrikcom_fabrik | 2 | Critical, High | 2026-08-22 | CVE-2026-76571CVE-2026-76596CVE-2026-76597CVE-2026-76598CVE-2026-76600CVE-2026-76601CVE-2026-76602CVE-2026-76603CVE-2026-76604CVE-2026-76605CVE-2026-76606CVE-2026-76607CVE-2026-76608CVE-2026-76609CVE-2026-77027CVE-2026-77992CVE-2026-76599CVE-2020-37219CVE-2026-67282CVE-2026-66915 |
| Gridboxcom_gridbox | 2 | Critical | 2026-08-10 | CVE-2026-61425CVE-2026-65884CVE-2026-65885CVE-2026-65889CVE-2026-65890CVE-2026-66488CVE-2026-66489CVE-2026-66490CVE-2026-65886CVE-2026-65887CVE-2026-65888CVE-2026-65947 |
| jDownloadscom_jdownloads | 2 | Critical, Medium | 2026-07-17 | CVE-2026-61900CVE-2025-55758CVE-2022-27909 |
| JEventscom_jevents | 2 | Critical | 2025-01-01 | CVE-2025-49467CVE-2015-7340 |
| K2com_k2 | 2 | Critical, Medium | 2026-06-25 | CVE-2026-48941CVE-2026-48942CVE-2026-48943CVE-2026-48944CVE-2026-48945CVE-2026-48946CVE-2026-48940 |
| Smart Slider 3 Prosmartslider3 | 2 | Critical, Medium | 2026-04-08 | CVE-2026-34424 |
| AcyMailingcom_acym | 1 | Critical | 2026-07-09 | CVE-2026-56292CVE-2023-39970CVE-2023-39971CVE-2023-39972CVE-2023-39973CVE-2023-39974 |
| Aimy Captcha-Less Form Guardaimycaptchalessformguard | 1 | Critical | 2026-07-28 | CVE-2026-65883 |
| Articles Anywherearticlesanywhere | 1 | Critical | 2026-07-22 | CVE-2026-64793CVE-2026-64794CVE-2026-64795CVE-2026-64799CVE-2026-65755 |
| Articles Calendarmod_articles_calendar | 1 | Critical | 2025-07-18 | CVE-2025-26855 |
| Articles Calendararticlescalendar | 1 | Critical | 2025-07-18 | CVE-2025-26855 |
| Astroid Frameworkastroid | 1 | Critical | 2026-03-05 | CVE-2026-21628 |
| BrainCert Virtual Classroomcom_virtualclassroom | 1 | Critical | 2023-08-07 | CVE-2023-34477 |
| Creative Contact Formcom_creativecontactform | 1 | Critical | 2020-03-04 | CVE-2014-8739CVE-2020-9364 |
| DJ-Classifiedscom_djclassifieds | 1 | Critical | 2026-07-20 | CVE-2026-61424CVE-2025-54474 |
| EDocmancom_edocman | 1 | Critical | 2026-07-14 | CVE-2026-57832 |
| Helix3 Templateshaper_helix3 | 1 | Critical | 2026-06-29 | CVE-2026-49049 |
| JEM - Joomla Event Managercom_jem | 1 | Critical | 2026-08-27 | CVE-2026-77034CVE-2026-77035CVE-2026-77989CVE-2026-77990CVE-2026-77991 |
| JooDatabasecom_joodb | 1 | Critical | 2026-09-03 | CVE-2026-78080 |
| JoomCCKcom_joomcck | 1 | Critical | 2026-07-17 | CVE-2026-49048 |
| LMS Litecom_lmslite | 1 | Critical | 2023-12-14 | CVE-2023-40629 |
| Modules Anywheremodulesanywhere | 1 | Critical | 2026-07-22 | CVE-2026-65757CVE-2026-64793CVE-2026-64795 |
| Regular Labs GeoIPgeoip | 1 | Critical | 2026-07-23 | CVE-2026-65431CVE-2026-64876CVE-2026-65430CVE-2026-64875 |
| RSFiles!com_rsfiles | 1 | Critical | 2026-07-10 | CVE-2026-57827CVE-2025-50057 |
| RSForm!Procom_rsform | 1 | Critical | 2025-01-01 | CVE-2025-30085CVE-2025-27444 |
| SP LMScom_splms | 1 | Critical | 2026-01-01 | CVE-2026-48909 |
| Starshopcom_starshop | 1 | Critical | 2023-12-14 | CVE-2023-49708 |
| Visitors Countermod_vvisit_counter | 1 | Critical | 2025-10-03 | CVE-2025-40636 |
| DPCalendarcom_dpcalendar | 7 | High, Medium | 2026-08-28 | CVE-2026-78071CVE-2026-78070CVE-2026-57831CVE-2024-21727 |
| YOOtheme Proyootheme | 6 | High, Medium | 2026-08-25 | CVE-2026-77997CVE-2026-76613CVE-2026-75115 |
| Convert Formscom_convertforms | 5 | High | 2026-07-23 | CVE-2026-65758CVE-2024-40744CVE-2024-40745CVE-2025-22212CVE-2026-77026 |
| Visformscom_visforms | 4 | High | - | CVE-2023-23753 |
| miniOrange LDAP Integrationcom_miniorange_dirsync | 2 | High | 2026-08-31 | CVE-2026-78074CVE-2023-23749 |
| Phoca Commandercom_phocacommander | 2 | High | 2026-07-27 | CVE-2026-65764CVE-2026-65765CVE-2025-54473CVE-2026-66491CVE-2026-66492CVE-2026-66493 |
| Sexy Polling Reloadedcom_sexypolling | 2 | High | 2026-08-28 | CVE-2026-78072 |
| YOOtheme Prolocation | 2 | High | 2026-08-25 | CVE-2026-77996 |
| 4Analyticscom_foranalytics | 1 | High | 2026-07-15 | CVE-2026-58077CVE-2026-57833 |
| AcyMailingcom_acymailing | 1 | High | 2020-03-09 | CVE-2015-7338 |
| Admiror Framesadmirorframes | 1 | High | 2024-06-28 | CVE-2024-5735CVE-2024-5736CVE-2024-5737 |
| ChronoForms 8com_chronoforms8 | 1 | High | 2026-07-17 | CVE-2026-58148 |
| Easy Shopcom_easyshop | 1 | High | 2019-01-01 | CVE-2019-25760 |
| EasyDiscusscom_easydiscuss | 1 | High | 2026-01-16 | CVE-2026-21623CVE-2026-21624CVE-2026-21625CVE-2026-21626 |
| EasyStorecom_easystore | 1 | High | - | CVE-2026-65759CVE-2026-65760CVE-2026-65761 |
| Event Registration Pro Calendarcom_registrationpro | 1 | High | 2017-01-01 | CVE-2017-20273 |
| Extra Searchcom_extrasearch | 1 | High | 2017-01-01 | CVE-2017-20281 |
| Flip Wallcom_flipwall | 1 | High | 2026-06-19 | CVE-2017-20265 |
| HDW Playercom_hdwplayer | 1 | High | 2026-05-13 | CVE-2020-37218 |
| Ignite Gallerycom_igallery | 1 | High | 2026-07-07 | - |
| J-ClassifiedsManagercom_displayads | 1 | High | 2019-01-01 | CVE-2019-25751 |
| J-MultipleHotelReservationcom_jmultiplehotelreservation | 1 | High | 2019-01-01 | CVE-2019-25750 |
| jCartcom_jcart | 1 | High | 2017-01-01 | CVE-2017-20282 |
| JHotelReservationcom_jhotelreservation | 1 | High | 2019-01-01 | CVE-2019-25748 |
| jNewscom_jnews | 1 | High | 2020-03-09 | CVE-2015-7341CVE-2015-7342CVE-2015-7343 |
| Jomrescom_jomres | 1 | High | 2026-05-23 | CVE-2013-3931CVE-2013-3932CVE-2018-25354 |
| JoomCRMcom_joomcrm | 1 | High | 2019-01-01 | CVE-2019-25761 |
| Joomdlecom_joomdle | 1 | High | 2026-07-28 | CVE-2026-65881CVE-2026-65882 |
| JoomGallerycom_joomgallery | 1 | High | 2026-08-22 | CVE-2026-66917CVE-2026-66916 |
| LMS King Professionalcom_lmsking | 1 | High | 2017-01-01 | CVE-2017-20274 |
| miniOrange Custom APIcom_miniorange_customapi | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange Import Export Userscom_miniorange_importexportusers | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange Keycloak User Synccom_miniorange_keycloaksync | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange Restrict Files / Folderscom_miniorange_mediarestriction | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange SCIM User Provisioningcom_miniorange_scim | 1 | High | 2026-08-31 | CVE-2026-78074 |
| miniOrange Two Factor Authenticationcom_miniorange_twofa | 1 | High | 2026-08-31 | CVE-2026-78074 |
| MyPortfoliocom_myportfolio | 1 | High | 2017-01-01 | CVE-2017-20280 |
| paGO Commercecom_pago | 1 | High | 2020-09-18 | CVE-2020-25751 |
| PHP-Bridgecom_phpbridge | 1 | High | 2017-01-01 | CVE-2017-20275 |
| Quantum Managercom_quantummanager | 1 | High | 2025-08-25 | CVE-2025-54300CVE-2025-54301 |
| Quix Page Buildercom_quix | 1 | High | 2026-07-15 | CVE-2026-58078CVE-2026-60026CVE-2026-60027CVE-2026-60028CVE-2026-60029CVE-2026-60030CVE-2026-60031 |
| Regular Labs DB Replacercom_dbreplacer | 1 | High | 2026-07-22 | CVE-2026-63685CVE-2026-63265 |
| Regular Labs Extension Managercom_regularlabsmanager | 1 | High | 2026-07-22 | CVE-2026-64791CVE-2026-63265 |
| Regular Labs IP Loginiplogin | 1 | High | 2026-07-22 | CVE-2026-64797CVE-2026-64798CVE-2026-63265 |
| RO CSVIcom_csvi | 1 | High | 2026-07-28 | CVE-2026-65943CVE-2026-65944CVE-2026-65946 |
| S5 Registermod_s5_register | 1 | High | 2023-12-14 | CVE-2023-49707 |
| StreetGuessr Gamecom_streetguess | 1 | High | 2017-01-01 | CVE-2017-20271 |
| Survey Force Deluxecom_surveyforce | 1 | High | 2026-06-19 | CVE-2017-20256 |
| T4 Page Buildercom_t4pagebuilder | 1 | High | 2026-08-28 | - |
| Twitch TVcom_twitchtv | 1 | High | 2017-01-01 | CVE-2017-20270 |
| Ultimate Property Listingcom_upl | 1 | High | 2017-01-01 | CVE-2017-20272 |
| Users Anywhereusersanywhere | 1 | High | 2026-07-22 | CVE-2026-64794CVE-2026-64795CVE-2026-64799CVE-2026-65755 |
| vAccountcom_vaccount | 1 | High | 2019-01-01 | CVE-2019-25756 |
| vBizzcom_vbizz | 1 | High | 2019-01-01 | CVE-2019-25758CVE-2019-25759 |
| VMapcom_vmap | 1 | High | 2019-01-01 | CVE-2019-25753 |
| vReviewcom_vreview | 1 | High | 2019-01-01 | CVE-2019-25755 |
| vWishlistcom_vwishlist | 1 | High | 2019-01-01 | CVE-2019-25757 |
| JoomShoppingcom_jshopping | 2 | Medium, Low | 2026-07-22 | CVE-2026-63264CVE-2025-22211 |
| Phoca Mapscom_phocamaps | 2 | Medium | 2026-07-23 | CVE-2026-65763CVE-2026-23900 |
| All Video Sharecom_allvideoshare | 1 | Medium | 2026-08-28 | CVE-2026-78073 |
| Balbooa Gallerycom_bagallery | 1 | Medium | 2025-07-18 | CVE-2025-49486CVE-2023-23757 |
| Balbooa Gallerycom_gallery | 1 | Medium | 2026-08-18 | - |
| Booking - Book Itcom_booking | 1 | Medium | 2023-01-01 | CVE-2023-54357 |
| CCommentcom_comment | 1 | Medium | 2025-07-23 | CVE-2025-54297 |
| Clicky Analytics Dashboardmod_clicky_dash | 1 | Medium | 2023-12-14 | CVE-2023-40658 |
| DJ-HelpfulArticlescom_djhelpfularticles | 1 | Medium | 2024-07-09 | CVE-2024-27183 |
| Easy Quick Contactmod_easyquickcontact | 1 | Medium | 2023-12-14 | CVE-2023-40659 |
| iProperty Real Estatecom_iproperty | 1 | Medium | 2026-04-09 | CVE-2023-54361 |
| JLex Reviewcom_jlexreview | 1 | Medium | 2026-04-09 | CVE-2023-54360 |
| JoomProjectcom_jpprojects | 1 | Medium | 2019-01-01 | CVE-2019-25762 |
| JS Jobscom_jsjobs | 1 | Medium | 2026-06-04 | CVE-2019-25740CVE-2018-25327CVE-2025-22206CVE-2025-22208CVE-2025-22209CVE-2025-49484CVE-2025-54475 |
| LivingWordcom_livingword | 1 | Medium | 2023-12-14 | CVE-2023-40627 |
| Membership Procom_osmembership | 1 | Medium | 2026-07-21 | CVE-2026-62415 |
| oneVotecom_onevote | 1 | Medium | 2023-07-11 | CVE-2023-23756 |
| osTicky2com_osticky2 | 1 | Medium | 2024-02-15 | CVE-2024-21728 |
| Phoca Guestbookcom_phocaguestbook | 1 | Medium | 2026-07-23 | CVE-2026-65762 |
| Regular Labs Advanced Module Managercom_advancedmodules | 1 | Medium | 2026-07-22 | CVE-2026-63280CVE-2026-63281CVE-2026-63683CVE-2026-63265 |
| Regular Labs Better Frontend Linkmod_betterfrontendlink | 1 | Medium | 2026-07-22 | CVE-2026-63265 |
| Regular Labs CDNcdnforjoomla | 1 | Medium | 2026-07-22 | CVE-2026-65712CVE-2026-63265 |
| Regular Labs Conditional Contentconditionalcontent | 1 | Medium | 2026-07-22 | CVE-2026-63280CVE-2026-63281CVE-2026-63683CVE-2026-64792 |
| Regular Labs Content Templatercom_contenttemplater | 1 | Medium | 2026-07-22 | CVE-2026-63684CVE-2026-63280CVE-2026-63281CVE-2026-63683 |
| Regular Labs Email Protectoremailprotector | 1 | Medium | 2026-07-22 | CVE-2026-63265 |
| Regular Labs Quick Indexquickindex | 1 | Medium | 2026-07-22 | CVE-2026-63265 |
| Regular Labs ReReplacercom_rereplacer | 1 | Medium | 2026-07-22 | CVE-2026-65754CVE-2026-63684CVE-2026-63280CVE-2026-63281 |
| Regular Labs Snippetscom_snippets | 1 | Medium | 2026-07-22 | CVE-2026-63684CVE-2026-64792CVE-2026-63265 |
| Regular Labs Tabs & Accordionstabsaccordions | 1 | Medium | 2026-07-22 | CVE-2026-64792CVE-2026-63265 |
| RSBlog!com_rsblog | 1 | Medium | 2025-01-01 | CVE-2025-50126CVE-2025-27754 |
| Solidrescom_solidres | 1 | Medium | 2026-04-09 | CVE-2023-54363 |
| VirtueMartcom_virtuemart | 1 | Medium | 2026-04-09 | CVE-2023-54362CVE-2025-25228CVE-2025-55757 |
| XCloner Backupcom_xcloner-backupandrestore | 1 | Medium | 2020-05-23 | CVE-2020-13424 |
| HikaShopcom_hikashop | 1 | Low | 2026-07-20 | CVE-2026-61901CVE-2023-38044CVE-2024-40746CVE-2025-22210CVE-2025-25225CVE-2015-7344 |
| SEBLODcom_cck | 3 | Unrated | - | CVE-2026-66914 |
| Cotton Cloudcom_cotton | 2 | Unrated | - | CVE-2026-67283CVE-2026-67284 |
| Admiror Gallerycom_admirorgallery | 1 | Unrated | - | CVE-2025-22205CVE-2023-38045 |
| Ajax Quizcom_ajaxquiz | 1 | Unrated | - | CVE-2017-20262 |
| Cache Cleanercachecleaner | 1 | Unrated | - | CVE-2026-64871CVE-2026-64872CVE-2026-64873CVE-2026-64874 |
| CommentBoxcom_commentbox | 1 | Unrated | - | CVE-2025-54298 |
| Creative Gallerycom_creativegallery | 1 | Unrated | - | CVE-2023-23758 |
| DJ-Flyercom_djflyer | 1 | Unrated | - | CVE-2025-50127 |
| DJ-Reviewscom_djreviews | 1 | Unrated | - | CVE-2025-54295 |
| DOCmancom_docman | 1 | Unrated | - | CVE-2022-27910 |
| eXtplorercom_extplorer | 1 | Unrated | - | CVE-2023-40628 |
| FocalPointcom_focalpoint | 1 | Unrated | - | CVE-2017-20263 |
| Gurucom_guru | 1 | Unrated | - | CVE-2022-23802 |
| iCagenda Calendar modulemod_icagenda_calendar | 1 | Unrated | - | CVE-2026-67365 |
| JCDashboardscom_jcdashboards | 1 | Unrated | - | CVE-2023-40630 |
| JMediacom_jmedia | 1 | Unrated | - | CVE-2026-60032CVE-2026-60033CVE-2026-60034 |
| JoomDOCcom_joomdoc | 1 | Unrated | - | CVE-2023-40657 |
| Joomla Quiz Deluxecom_joomlaquiz | 1 | Unrated | - | CVE-2017-20257 |
| JoomRecipecom_joomrecipe | 1 | Unrated | - | CVE-2017-20277CVE-2017-20278 |
| Keyboard Shortcutskeyboardshortcuts | 1 | Unrated | - | CVE-2026-65756 |
| Komentocom_komento | 1 | Unrated | - | CVE-2025-54294 |
| Modalsmodals | 1 | Unrated | - | CVE-2026-65713 |
| No Boss Calendarcom_nobosscalendar | 1 | Unrated | - | CVE-2025-49468 |
| No Boss Testimonialscom_nobosstestimonials | 1 | Unrated | - | CVE-2025-54299 |
| OSDownloadscom_osdownloads | 1 | Unrated | - | CVE-2017-20259 |
| Payagecom_payage | 1 | Unrated | - | CVE-2017-20279 |
| ProFilescom_profiles | 1 | Unrated | - | CVE-2025-54296 |
| Proforms Basiccom_proforms | 1 | Unrated | - | CVE-2023-34476CVE-2023-40655 |
| QuickFormcom_quickform | 1 | Unrated | - | CVE-2023-40656 |
| RSDirectory!com_rsdirectory | 1 | Unrated | - | CVE-2025-50058 |
| RSFirewall!com_rsfirewall | 1 | Unrated | - | CVE-2025-27445 |
| RSMail!com_rsmail | 1 | Unrated | - | CVE-2025-50056CVE-2025-30084 |
| RSMediaGallery!com_rsmediagallery | 1 | Unrated | - | CVE-2025-27753CVE-2025-32466 |
| RSTickets! Procom_rsticketspro | 1 | Unrated | - | CVE-2025-32465 |
| SIMGenealogycom_simgenealogy | 1 | Unrated | - | CVE-2017-20276 |
| SP Movie Databasecom_spmoviedb | 1 | Unrated | - | CVE-2017-20266 |
| SP Property Findercom_spproperty | 1 | Unrated | - | - |
| Sponsor Wallcom_sponsorwall | 1 | Unrated | - | CVE-2017-20264 |
| Tooltipstooltips | 1 | Unrated | - | - |
| Zap Calendarcom_zcalendar | 1 | Unrated | - | CVE-2017-20268 |
No extension matches that.
Vulnerabilities we found and disclosed
66 write-ups. Every one was reported privately to the developer first.

T4 Page Builder 2.3.0 Fixes an Unauthenticated Mail Relay
JoomlArt's T4 Page Builder 2.3.0 closes an unauthenticated open mail relay we reported in August. A week on, five in six installs we see are still older.

J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws we reported
J2Store 3.3.22, 4.0.22 and 4.1.7 fix five flaws mySites.guru reported, including anonymous PayPal order confirmation and a 9.5 backend escalation.

DPCalendar 10.12.0 fixes an SQL injection and an XSS
Digital Peak fixed a blind SQL injection and a stored XSS in DPCalendar 10.12.0, backported to 8.19.5 for Joomla 3. Both need a logged-in user.

Helix Ultimate 2.2.10 Fixes Twelve Security Issues, Including a Pre-Login Bypass
Helix Ultimate 2.2.10 is a security release for the Joomla template framework. Every version below it is affected. Here is what it fixes and how to update.

Helix Ultimate's Third Joomla 3 Patch Since JoomShaper Said There Would Be None
JoomShaper said its Joomla 3 products would get no security patches regardless of severity. The Helix Ultimate template framework has now had four.

Three CVEs in miniOrange Extensions for Joomla, All Now Fixed
Two CVSS 10.0 authentication bypasses and a remote uninstall flaw naming 23 extensions. Every affected free edition now has a fixed version, released 31 August.

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes
Fabrik 4.7.2 for the Joomla extension closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Update now.

Five Security Issues in JEM (Joomla Event Manager), and No Stable Fix Yet
mySites.guru found and reported multiple security issues in JEM (Joomla Event Manager), including an unauthenticated article overwrite. No stable fix yet.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66
YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.

iCagenda 4.0.12 fixes an unauthenticated SQL injection
CVE-2026-67365 is an unauthenticated SQL injection in the iCagenda Calendar module for Joomla, scored 9.2 Critical. Fixed in 4.0.12.

Sourcerer 14 and 15 did not fix CVE-2026-74253. 16.0.0 does.
Sourcerer 14 and 15 were both published as the fix for CVE-2026-74253 and neither closed it. It is exploited in the wild. Update now to 16.0.0.

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection
Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 on 6.x isn't offered it.