Joomdle
Affected versions: ≥ 1.0.2 and ≤ 3.0.1
Full advisory: www.joomdle.com
Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE
Joomdle bridges a Joomla site to a Moodle installation. Every release from 0.7.0 up to and including 3.0.1 ships an insecure default configuration (CVE-2026-65881): out of the box the extension exposes read access to Joomla user accounts and allows a password reset of those accounts, so anyone who can reach the integration endpoint can enumerate CMS users and take over an account without ever authenticating to Joomla. The same releases carry a reflected XSS (CVE-2026-65882) in the goto URL parameter of the Moodle wrapper endpoint. Fixed in Joomdle 3.1.1. Update to 3.1.1 or later, then review the Joomdle configuration against the vendor defaults and audit the Joomla user list for unfamiliar accounts and unexpected password changes. NOTE ON THE VERSION FLOOR: this rule starts at 1.0.2 rather than the vendor floor of 0.7.0 because the separate "Xmap - Joomdle Plugin" ships under element com_joomdle at version 1.0.1, and match_extension_type is not currently enforced by the matcher; the floor keeps that sitemap plugin from being flagged. The trade-off is that a genuine Joomdle component below 1.0.2 (0.95 and earlier) is not caught by this rule.
Affected versions: ≥ 1.0.2 and ≤ 3.0.1
Official record: cve.org · NVD
Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.
Joomdle
Affected versions: ≥ 1.0.2 and ≤ 3.0.1
Full advisory: www.joomdle.com
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
Rules current as of 25 August 2026.