Skip to main content
mySites.guru
5+ live

Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE

CVE-2026-58077HighPublished 15 July 2026

4Analytics (com_foranalytics) below 5.0.2 - Unauthenticated Stored XSS (website takeover)

All versions of the Weeblr 4Analytics extension for Joomla up to and including 5.0.1 are affected by two critical unauthenticated stored XSS vulnerabilities, both rated High (CVSS 4.0 base 8.7 and 8.6) and both reported by the vendor. CVE-2026-58077: a specially crafted unauthenticated request stores malicious script that, under some circumstances, can result in a full website takeover. CVE-2026-57833: a second unauthenticated stored XSS reached through the AI analysis feature, where attacker-controlled content was rendered from Markdown to HTML without safe mode. No authentication and no account on the site are required to exploit either issue, so any site running an affected version is reachable by an anonymous attacker on the internet. The vendor released 5.0.2 on 15 July 2026 as an emergency security release covering both issues, and it runs on Joomla 3, 4, 5 and 6. Update to 4Analytics 5.0.2 or later immediately. If you cannot update straight away, unpublish the 4Analytics system plugin to stop the unauthenticated tracking endpoint from accepting requests. Note that the vendor is withholding technical details until roughly 22 July 2026 to give sites time to update, so expect exploitation attempts to follow that disclosure.

Affected versions: < 5.0.2

Official record: cve.org · NVD

Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.

Affected extensions and versions

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 25 August 2026.