Skip to main content
mySites.guru
5+ live

Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE

CVE-2026-65883CriticalPublished 28 July 2026

Aimy Captcha-Less Form Guard (aimycaptchalessformguard) 18.0 to 20.0 - Unauthenticated PHP Object Injection leading to Remote Code Execution

Aimy Captcha-Less Form Guard versions 18.0 through 20.0 contain an unauthenticated PHP object injection flaw that leads to remote code execution. A forged "clfgd" field submitted to the plugin is deserialised without validation, so an attacker who supplies a crafted value can instantiate arbitrary PHP objects and, with a suitable gadget chain, execute code on the server. This is a captcha plugin that runs on public-facing forms, so the vulnerable code path is reachable by anonymous visitors: no account, no session and no user interaction are required. NVD scores it CVSS 4.0 base 10.0 Critical (AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H). Tracked as CVE-2026-65883, published 29 July 2026; the vendor had shipped 20.1 on 28 July 2026 as a security release before the technical detail was public. Both the free and the PRO edition install under the same element and share one version numbering scheme, so both editions are affected. There is no mitigation short of updating, because the fix ships only in 20.1. Update to 20.1 or later from the Joomla backend, or download it from the vendor. Versions 17.0 and below are outside the range the vendor states as affected. Given this is an unauthenticated RCE on a public form handler, treat any site that ran 18.0 to 20.0 while exposed as potentially compromised and review it for unexpected PHP files and unrecognised administrator accounts.

Affected versions: ≥ 18.0 and < 20.1

Official record: cve.org · NVD

Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.

Affected extensions and versions

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 25 August 2026.