Regular Labs GeoIP
Affected versions: ≤ 6.3.8
Full advisory: regularlabs.com
Regular Labs GeoIP up to and including 6.3.8 is affected by four flaws disclosed through the Joomla CNA on 22-23 July 2026. CVE-2026-65431 (CVSS 9.8) is a Zipslip: the GeoIP database update archives are extracted without validating the paths inside them, so a crafted archive can write files anywhere the web user can reach, which is arbitrary file write leading to remote code execution. CVE-2026-64876 (CVSS 8.8) is inconsistent CSRF token and privilege checking across the extension's admin actions. CVE-2026-65430 (CVSS 7.5) leaks the configured MaxMind account credentials. CVE-2026-64875 (CVSS 6.5) allows IP spoofing, so any access rule, geo-restriction or content condition built on GeoIP can be bypassed by an unauthenticated visitor. Update to 7.0.0 or later; the vendor's current release is 7.0.3 (28 July 2026) and it is free. If you cannot update immediately, disable the GeoIP system plugin, and treat any geo-based access control as bypassable until you have.
Affected versions: ≤ 6.3.8
Official record: cve.org · NVD
Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.
Regular Labs GeoIP
Affected versions: ≤ 6.3.8
Full advisory: regularlabs.com
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
Rules current as of 13 September 2026.