Skip to main content
mySites.guru
5+ live

Joomla extension security alerts (22 Aug) Fabrik 4.7.2ZOO: unauth RCEPhoca Cart: unauth SQLiJCE 2.9.99.10SP Page Builder RCE

CVE-2026-76604CriticalPublished 22 August 2026

Fabrik (com_fabrik) 4.7.0 and 4.7.1 - Unauthenticated Remote Code Execution risk, update to 4.7.2

Fabrik (the Joomla form and list builder by Fabrikar) shipped a series of security releases across the 4.7.x line. 4.7.2 is the release mySites.guru has verified, and 4.7.0 and 4.7.1 are missing part of that work. The calc element in this component carried a published unauthenticated remote code execution vulnerability (CVE-2026-66915 and CVE-2026-67282, both CVSS 10.0). mySites.guru worked with Fabrikar through the 4.7.x releases under coordinated disclosure, and 4.7.2 closes the issues raised. What to do: update Fabrik to 4.7.2, downloaded from fabrikar.com. Until you have, restrict front-end access to Fabrik forms and lists to trusted users. Sites below 4.7.0 are covered by a separate rule and remain exposed to the published CVSS 10.0 RCE.

Affected versions: ≥ 4.7.0 and < 4.7.2

Official record: cve.org · NVD

Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.

Affected extensions and versions

Our disclosure post

Running an affected version on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

Rules current as of 25 August 2026.