Joomdle
Affected versions: ≥ 1.0.2 and ≤ 3.0.1
Full advisory: www.joomdle.com
Joomdle bridges a Joomla site to a Moodle installation. Every release from 0.7.0 up to and including 3.0.1 ships an insecure default configuration (CVE-2026-65881): out of the box the extension exposes read access to Joomla user accounts and allows a password reset of those accounts, so anyone who can reach the integration endpoint can enumerate CMS users and take over an account without ever authenticating to Joomla. The same releases carry a reflected XSS (CVE-2026-65882) in the goto URL parameter of the Moodle wrapper endpoint. Fixed in Joomdle 3.1.1. Update to 3.1.1 or later, then review the Joomdle configuration against the vendor defaults and audit the Joomla user list for unfamiliar accounts and unexpected password changes. NOTE ON THE VERSION FLOOR: this rule starts at 1.0.2 rather than the vendor floor of 0.7.0 because the separate "Xmap - Joomdle Plugin" ships under element com_joomdle at version 1.0.1, and match_extension_type is not currently enforced by the matcher; the floor keeps that sitemap plugin from being flagged. The trade-off is that a genuine Joomdle component below 1.0.2 (0.95 and earlier) is not caught by this rule.
The base metrics as CISA-ADP published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.
6.1 Medium
CVSS 3.1, scored by CISA-ADPCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:NThe rule below is rated High for the set of 2 CVEs it covers together, not for this record on its own.
Joomdle
Affected versions: ≥ 1.0.2 and ≤ 3.0.1
Full advisory: www.joomdle.com
Updating for CVE-2026-65882 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.
Rules current as of 5 October 2026.