Affected versions: < 2.20.2
Full advisory: our disclosure post
Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE
A full security audit of Gridbox (component com_gridbox) found 23 vulnerabilities, including an unauthenticated arbitrary file upload that yields remote code execution in a single request, multiple unauthenticated SQL injection points (one returns every user password hash), several routes to administrator access with no password, and a registration flaw that lets any visitor create an administrator account. Several are being actively exploited in the wild, confirmed by the Joomla Security Strike Team and observed by us in server logs and on compromised sites. The Joomla CNA has assigned CVE IDs grouped by shared root cause rather than one per finding. Published so far: CVE-2026-65884 (registration accepts user-supplied group IDs, so an anonymous visitor can register with administrator permissions; CWE-284; CVSS 4.0 10.0 Critical; exploit maturity Attacked) and CVE-2026-65885 (authenticated arbitrary file upload, which becomes remote code execution when chained with CVE-2026-65884 because the attacker can create the account it needs; CWE-434; CVSS 4.0 9.4 Critical; exploit maturity Attacked). Nine further IDs are reserved and not yet public: CVE-2026-65886, CVE-2026-65887, CVE-2026-65888, CVE-2026-65889, CVE-2026-65890, CVE-2026-65947, CVE-2026-66488, CVE-2026-66489 and CVE-2026-66490. A separate earlier authentication bypass, CVE-2026-61425, was fixed in 2.20.1. Fixed in the Gridbox 2.20.2 security release (29 July 2026): update every Gridbox site now. Every version before it, 1.0.0 to 2.20.1, is affected. Any site that has run an affected version may already be compromised: check for unexpected administrator accounts (in any group, not just Super Users), new or modified files, and PHP files in upload folders, and rotate administrator credentials. fix.mysites.guru can clean a compromised site (GBP 120, a single fixed fee, usually same day).
Affected versions: < 2.20.2
Official record: cve.org · NVD
Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.
Affected versions: < 2.20.2
Full advisory: our disclosure post
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
Rules current as of 25 August 2026.