Aimy Captcha-Less Form Guard
Affected versions: ≥ 18.0 and < 20.1
Full advisory: www.aimy-extensions.com
Aimy Captcha-Less Form Guard versions 18.0 through 20.0 contain an unauthenticated PHP object injection flaw that leads to remote code execution. A forged "clfgd" field submitted to the plugin is deserialised without validation, so an attacker who supplies a crafted value can instantiate arbitrary PHP objects and, with a suitable gadget chain, execute code on the server. This is a captcha plugin that runs on public-facing forms, so the vulnerable code path is reachable by anonymous visitors: no account, no session and no user interaction are required. NVD scores it CVSS 4.0 base 10.0 Critical (AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H). Tracked as CVE-2026-65883, published 29 July 2026; the vendor had shipped 20.1 on 28 July 2026 as a security release before the technical detail was public. Both the free and the PRO edition install under the same element and share one version numbering scheme, so both editions are affected. There is no mitigation short of updating, because the fix ships only in 20.1. Update to 20.1 or later from the Joomla backend, or download it from the vendor. Versions 17.0 and below are outside the range the vendor states as affected. Given this is an unauthenticated RCE on a public form handler, treat any site that ran 18.0 to 20.0 while exposed as potentially compromised and review it for unexpected PHP files and unrecognised administrator accounts.
The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.
10.0 Critical
CVSS 4.0, scored by Joomla CNACVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HAimy Captcha-Less Form Guard
Affected versions: ≥ 18.0 and < 20.1
Full advisory: www.aimy-extensions.com
Updating for CVE-2026-65883 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.
Latest safe version: 20.1
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.
Rules current as of 5 October 2026.