Skip to main content
mySites.guru
New features added last monthRelease RadarFile ManagerImpostor FilesUpdate QueueRogue AdminsMCP & APIJoomla VELCVE Index
CVE-2026-64876CriticalPublished 23 July 2026

Regular Labs GeoIP (geoip) <= 6.3.8 - Zipslip Arbitrary File Write (RCE), CSRF and Privilege Check Bypass, MaxMind Credential Leakage and IP Spoofing

Regular Labs GeoIP up to and including 6.3.8 is affected by four flaws disclosed through the Joomla CNA on 22-23 July 2026. CVE-2026-65431 (CVSS 9.8) is a Zipslip: the GeoIP database update archives are extracted without validating the paths inside them, so a crafted archive can write files anywhere the web user can reach, which is arbitrary file write leading to remote code execution. CVE-2026-64876 (CVSS 8.8) is inconsistent CSRF token and privilege checking across the extension's admin actions. CVE-2026-65430 (CVSS 7.5) leaks the configured MaxMind account credentials. CVE-2026-64875 (CVSS 6.5) allows IP spoofing, so any access rule, geo-restriction or content condition built on GeoIP can be bypassed by an unauthenticated visitor. Update to 7.0.0 or later; the vendor's current release is 7.0.3 (28 July 2026) and it is free. If you cannot update immediately, disable the GeoIP system plugin, and treat any geo-based access control as bypassable until you have.

Affected versions: ≤ 6.3.8

Official record: cve.org · NVD

Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.

Affected extensions and versions

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 13 September 2026.