<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>mySites.guru Joomla CVE index</title><description>CVE-numbered Joomla extension vulnerabilities as mySites.guru adds them to the database.</description><link>https://mysites.guru/</link><language>en-gb</language><atom:link rel="self" type="application/rss+xml" href="https://mysites.guru/vulnerabilities/cve/rss.xml"/><image><url>https://mysites.guru/favicon.svg</url><title>mySites.guru Joomla CVE index</title><link>https://mysites.guru/vulnerabilities/cve/</link></image><item><title>CVE-2026-81566 - SP Page Builder (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-81566/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-81566/</guid><description>Five security issues found by mySites.guru in SP Page Builder 6.9.0 and reported privately to JoomShaper on 8 September 2026, all fixed in 6.9.1 on 14 September 2026. No CVE identifiers have been assigned to this round. 1. Author-level blind SQL injection (CVSS 4.0 7.1 High, CWE-89). The com_content integration plugin reads a value from the article-save request without an integer cast and concatenates it into a query. Any account that can save an article, an Author on a default Joomla site, can read the entire database one character at a time, including the Super User password hash. Requires the SP Page Builder content plugin to be enabled, which it is on any site using the builder inside articles.
2. Unauthenticated captcha bypass (CVSS 4.0 6.9 Medium, CWE-287/CWE-804). The contact form, opt-in form and form builder addons discard the real captcha result whenever the request claims the form is rendered inside a module, and the opt-in form additionally compared two attacker-supplied values. An anonymous visitor defeats reCAPTCHA on any of the three. These addons ship only in SP Page Builder Pro, so the free Lite edition is not affected by this one.
3. Editor-level media file rename escaping the media folders (CVSS 4.0 7.2 High, CWE-22). Renaming a chosen file to a path outside the web root can take the site down.
4. Editor-level Joomla menu takeover (CVSS 4.0 7.1 High, CWE-862). The add-to-menu action called the menu-item model directly with no com_menus permission check, so an Editor could create or overwrite menu items including the site home item.
5. Author-level file write into the web root media tree (CVSS 4.0 5.3 Medium, CWE-862). The upload endpoint took its destination folder from the request without confining it. Update to SP Page Builder 6.9.1 or later. Joomla 3 sites cannot install 6.9.1: JoomShaper published a separate Joomla 3 Security Patch 1.0.2 which back-ports four of the five fixes, but it installs only over SP Page Builder 5.6.1 and does not change the component version, so patched and unpatched Joomla 3 sites are indistinguishable by version and are deliberately not covered by this rule.</description><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><category>SP Page Builder</category><category>High</category></item><item><title>CVE-2026-81565 - SP Page Builder (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-81565/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-81565/</guid><description>Five security issues found by mySites.guru in SP Page Builder 6.9.0 and reported privately to JoomShaper on 8 September 2026, all fixed in 6.9.1 on 14 September 2026. No CVE identifiers have been assigned to this round. 1. Author-level blind SQL injection (CVSS 4.0 7.1 High, CWE-89). The com_content integration plugin reads a value from the article-save request without an integer cast and concatenates it into a query. Any account that can save an article, an Author on a default Joomla site, can read the entire database one character at a time, including the Super User password hash. Requires the SP Page Builder content plugin to be enabled, which it is on any site using the builder inside articles.
2. Unauthenticated captcha bypass (CVSS 4.0 6.9 Medium, CWE-287/CWE-804). The contact form, opt-in form and form builder addons discard the real captcha result whenever the request claims the form is rendered inside a module, and the opt-in form additionally compared two attacker-supplied values. An anonymous visitor defeats reCAPTCHA on any of the three. These addons ship only in SP Page Builder Pro, so the free Lite edition is not affected by this one.
3. Editor-level media file rename escaping the media folders (CVSS 4.0 7.2 High, CWE-22). Renaming a chosen file to a path outside the web root can take the site down.
4. Editor-level Joomla menu takeover (CVSS 4.0 7.1 High, CWE-862). The add-to-menu action called the menu-item model directly with no com_menus permission check, so an Editor could create or overwrite menu items including the site home item.
5. Author-level file write into the web root media tree (CVSS 4.0 5.3 Medium, CWE-862). The upload endpoint took its destination folder from the request without confining it. Update to SP Page Builder 6.9.1 or later. Joomla 3 sites cannot install 6.9.1: JoomShaper published a separate Joomla 3 Security Patch 1.0.2 which back-ports four of the five fixes, but it installs only over SP Page Builder 5.6.1 and does not change the component version, so patched and unpatched Joomla 3 sites are indistinguishable by version and are deliberately not covered by this rule.</description><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><category>SP Page Builder</category><category>High</category></item><item><title>CVE-2026-81564 - SP Page Builder (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-81564/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-81564/</guid><description>Five security issues found by mySites.guru in SP Page Builder 6.9.0 and reported privately to JoomShaper on 8 September 2026, all fixed in 6.9.1 on 14 September 2026. No CVE identifiers have been assigned to this round. 1. Author-level blind SQL injection (CVSS 4.0 7.1 High, CWE-89). The com_content integration plugin reads a value from the article-save request without an integer cast and concatenates it into a query. Any account that can save an article, an Author on a default Joomla site, can read the entire database one character at a time, including the Super User password hash. Requires the SP Page Builder content plugin to be enabled, which it is on any site using the builder inside articles.
2. Unauthenticated captcha bypass (CVSS 4.0 6.9 Medium, CWE-287/CWE-804). The contact form, opt-in form and form builder addons discard the real captcha result whenever the request claims the form is rendered inside a module, and the opt-in form additionally compared two attacker-supplied values. An anonymous visitor defeats reCAPTCHA on any of the three. These addons ship only in SP Page Builder Pro, so the free Lite edition is not affected by this one.
3. Editor-level media file rename escaping the media folders (CVSS 4.0 7.2 High, CWE-22). Renaming a chosen file to a path outside the web root can take the site down.
4. Editor-level Joomla menu takeover (CVSS 4.0 7.1 High, CWE-862). The add-to-menu action called the menu-item model directly with no com_menus permission check, so an Editor could create or overwrite menu items including the site home item.
5. Author-level file write into the web root media tree (CVSS 4.0 5.3 Medium, CWE-862). The upload endpoint took its destination folder from the request without confining it. Update to SP Page Builder 6.9.1 or later. Joomla 3 sites cannot install 6.9.1: JoomShaper published a separate Joomla 3 Security Patch 1.0.2 which back-ports four of the five fixes, but it installs only over SP Page Builder 5.6.1 and does not change the component version, so patched and unpatched Joomla 3 sites are indistinguishable by version and are deliberately not covered by this rule.</description><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><category>SP Page Builder</category><category>High</category></item><item><title>CVE-2026-79701 - SP Page Builder (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-79701/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-79701/</guid><description>Five security issues found by mySites.guru in SP Page Builder 6.9.0 and reported privately to JoomShaper on 8 September 2026, all fixed in 6.9.1 on 14 September 2026. No CVE identifiers have been assigned to this round. 1. Author-level blind SQL injection (CVSS 4.0 7.1 High, CWE-89). The com_content integration plugin reads a value from the article-save request without an integer cast and concatenates it into a query. Any account that can save an article, an Author on a default Joomla site, can read the entire database one character at a time, including the Super User password hash. Requires the SP Page Builder content plugin to be enabled, which it is on any site using the builder inside articles.
2. Unauthenticated captcha bypass (CVSS 4.0 6.9 Medium, CWE-287/CWE-804). The contact form, opt-in form and form builder addons discard the real captcha result whenever the request claims the form is rendered inside a module, and the opt-in form additionally compared two attacker-supplied values. An anonymous visitor defeats reCAPTCHA on any of the three. These addons ship only in SP Page Builder Pro, so the free Lite edition is not affected by this one.
3. Editor-level media file rename escaping the media folders (CVSS 4.0 7.2 High, CWE-22). Renaming a chosen file to a path outside the web root can take the site down.
4. Editor-level Joomla menu takeover (CVSS 4.0 7.1 High, CWE-862). The add-to-menu action called the menu-item model directly with no com_menus permission check, so an Editor could create or overwrite menu items including the site home item.
5. Author-level file write into the web root media tree (CVSS 4.0 5.3 Medium, CWE-862). The upload endpoint took its destination folder from the request without confining it. Update to SP Page Builder 6.9.1 or later. Joomla 3 sites cannot install 6.9.1: JoomShaper published a separate Joomla 3 Security Patch 1.0.2 which back-ports four of the five fixes, but it installs only over SP Page Builder 5.6.1 and does not change the component version, so patched and unpatched Joomla 3 sites are indistinguishable by version and are deliberately not covered by this rule.</description><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><category>SP Page Builder</category><category>High</category></item><item><title>CVE-2026-79700 - SP Page Builder (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-79700/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-79700/</guid><description>Five security issues found by mySites.guru in SP Page Builder 6.9.0 and reported privately to JoomShaper on 8 September 2026, all fixed in 6.9.1 on 14 September 2026. No CVE identifiers have been assigned to this round. 1. Author-level blind SQL injection (CVSS 4.0 7.1 High, CWE-89). The com_content integration plugin reads a value from the article-save request without an integer cast and concatenates it into a query. Any account that can save an article, an Author on a default Joomla site, can read the entire database one character at a time, including the Super User password hash. Requires the SP Page Builder content plugin to be enabled, which it is on any site using the builder inside articles.
2. Unauthenticated captcha bypass (CVSS 4.0 6.9 Medium, CWE-287/CWE-804). The contact form, opt-in form and form builder addons discard the real captcha result whenever the request claims the form is rendered inside a module, and the opt-in form additionally compared two attacker-supplied values. An anonymous visitor defeats reCAPTCHA on any of the three. These addons ship only in SP Page Builder Pro, so the free Lite edition is not affected by this one.
3. Editor-level media file rename escaping the media folders (CVSS 4.0 7.2 High, CWE-22). Renaming a chosen file to a path outside the web root can take the site down.
4. Editor-level Joomla menu takeover (CVSS 4.0 7.1 High, CWE-862). The add-to-menu action called the menu-item model directly with no com_menus permission check, so an Editor could create or overwrite menu items including the site home item.
5. Author-level file write into the web root media tree (CVSS 4.0 5.3 Medium, CWE-862). The upload endpoint took its destination folder from the request without confining it. Update to SP Page Builder 6.9.1 or later. Joomla 3 sites cannot install 6.9.1: JoomShaper published a separate Joomla 3 Security Patch 1.0.2 which back-ports four of the five fixes, but it installs only over SP Page Builder 5.6.1 and does not change the component version, so patched and unpatched Joomla 3 sites are indistinguishable by version and are deliberately not covered by this rule.</description><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><category>SP Page Builder</category><category>High</category></item><item><title>CVE-2026-78375 - SP Page Builder (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78375/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78375/</guid><description>Five security issues found by mySites.guru in SP Page Builder 6.9.0 and reported privately to JoomShaper on 8 September 2026, all fixed in 6.9.1 on 14 September 2026. No CVE identifiers have been assigned to this round. 1. Author-level blind SQL injection (CVSS 4.0 7.1 High, CWE-89). The com_content integration plugin reads a value from the article-save request without an integer cast and concatenates it into a query. Any account that can save an article, an Author on a default Joomla site, can read the entire database one character at a time, including the Super User password hash. Requires the SP Page Builder content plugin to be enabled, which it is on any site using the builder inside articles.
2. Unauthenticated captcha bypass (CVSS 4.0 6.9 Medium, CWE-287/CWE-804). The contact form, opt-in form and form builder addons discard the real captcha result whenever the request claims the form is rendered inside a module, and the opt-in form additionally compared two attacker-supplied values. An anonymous visitor defeats reCAPTCHA on any of the three. These addons ship only in SP Page Builder Pro, so the free Lite edition is not affected by this one.
3. Editor-level media file rename escaping the media folders (CVSS 4.0 7.2 High, CWE-22). Renaming a chosen file to a path outside the web root can take the site down.
4. Editor-level Joomla menu takeover (CVSS 4.0 7.1 High, CWE-862). The add-to-menu action called the menu-item model directly with no com_menus permission check, so an Editor could create or overwrite menu items including the site home item.
5. Author-level file write into the web root media tree (CVSS 4.0 5.3 Medium, CWE-862). The upload endpoint took its destination folder from the request without confining it. Update to SP Page Builder 6.9.1 or later. Joomla 3 sites cannot install 6.9.1: JoomShaper published a separate Joomla 3 Security Patch 1.0.2 which back-ports four of the five fixes, but it installs only over SP Page Builder 5.6.1 and does not change the component version, so patched and unpatched Joomla 3 sites are indistinguishable by version and are deliberately not covered by this rule.</description><pubDate>Mon, 14 Sep 2026 00:00:00 GMT</pubDate><category>SP Page Builder</category><category>High</category></item><item><title>CVE-2026-88853 - Modals (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-88853/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-88853/</guid><description>Regular Labs Modals 16.0.0 through 16.2.0 is affected by two vendor-confirmed security defects, both fixed in 17.0.0 (released 13 September 2026). CVE-2026-85189: modal links accepted javascript: URLs, so a crafted link executed script when the modal was opened. CVE-2026-88853: JavaScript Events could be attached by any user able to author content; 17.0.0 restricts them to selected article author groups by default. Both require the ability to author or edit content containing Modals links or tags, making this an authenticated stored XSS. Update to 17.0.0 or later. Note that 17.0.0 is flagged by the vendor as a BC BREAK: the JavaScript Events restriction is enabled by default and has to be re-opened deliberately per author group, so review those settings after updating. The CVE records were published on 14 September 2026: CVE-2026-85189 at CVSS 4.0 7.5 (High), vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N; CVE-2026-88853 at CVSS 4.0 7.5 (High), vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Modals</category><category>High</category></item><item><title>CVE-2026-88852 - Snippets (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-88852/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-88852/</guid><description>Regular Labs Snippets 10.0.0 through 10.0.6 is affected by CVE-2026-88852, fixed in 11.0.0 (released 13 September 2026). Snippet variable overrides could be set by any user able to author content, letting a lower-privileged author change the values a snippet renders and inject script through them. 11.0.0 restricts variable overrides to selected article author groups by default. Exploitation requires the ability to author or edit content containing Snippets tags, so this is an authenticated stored XSS. Update to 11.0.0 or later. Note that 11.0.0 is flagged by the vendor as a BC BREAK: the restriction is enabled by default and has to be re-opened deliberately per author group, so any site relying on variable overrides should review those settings after updating. The CVE record was published on 14 September 2026 with a CVSS 4.0 base score of 7.5 (High), vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Snippets</category><category>High</category></item><item><title>CVE-2026-85196 - Articles Anywhere, Users Anywhere (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85196/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-85196/</guid><description>Regular Labs Articles Anywhere 19.0.0 through 19.0.6 is affected by two vendor-confirmed security defects, both fixed in 20.0.0 (released 13 September 2026). CVE-2026-85196: request input consumed by Articles Anywhere data tags was not escaped, and the optional raw output mode was available to any article author, allowing script to be injected into rendered article content. CVE-2026-85195: JavaScript Events could be attached by any user able to author article content; 20.0.0 restricts them to selected article author groups by default. Exploitation requires the ability to author or edit content containing Articles Anywhere tags, or a page that already feeds request input into one, so this is an authenticated stored XSS with a reflected vector on affected pages. Update to 20.0.0 or later. Note that 20.0.0 is flagged by the vendor as a BC BREAK: the JavaScript Events restriction is enabled by default and has to be re-opened deliberately per author group, so review those settings after updating. The same release also tightens destination checks for external image downloads, which the vendor did not label a security fix. The CVE records were published on 14 September 2026: CVE-2026-85195 at CVSS 4.0 7.5 (High), vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N; CVE-2026-85196 at CVSS 4.0 5.3 (Medium), vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Articles Anywhere</category><category>Users Anywhere</category><category>High</category></item><item><title>CVE-2026-85195 - Articles Anywhere (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85195/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-85195/</guid><description>Regular Labs Articles Anywhere 19.0.0 through 19.0.6 is affected by two vendor-confirmed security defects, both fixed in 20.0.0 (released 13 September 2026). CVE-2026-85196: request input consumed by Articles Anywhere data tags was not escaped, and the optional raw output mode was available to any article author, allowing script to be injected into rendered article content. CVE-2026-85195: JavaScript Events could be attached by any user able to author article content; 20.0.0 restricts them to selected article author groups by default. Exploitation requires the ability to author or edit content containing Articles Anywhere tags, or a page that already feeds request input into one, so this is an authenticated stored XSS with a reflected vector on affected pages. Update to 20.0.0 or later. Note that 20.0.0 is flagged by the vendor as a BC BREAK: the JavaScript Events restriction is enabled by default and has to be re-opened deliberately per author group, so review those settings after updating. The same release also tightens destination checks for external image downloads, which the vendor did not label a security fix. The CVE records were published on 14 September 2026: CVE-2026-85195 at CVSS 4.0 7.5 (High), vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N; CVE-2026-85196 at CVSS 4.0 5.3 (Medium), vector CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Articles Anywhere</category><category>High</category></item><item><title>CVE-2026-85192 - Conditional Content (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85192/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-85192/</guid><description>Regular Labs Conditional Content 7.0.0 through 7.1.0 is affected by two vendor-confirmed security defects, both fixed in 8.0.0 (released 13 September 2026). CVE-2026-85192 is the more serious and the most serious item in the whole 13 September batch: untrusted article authors could run PHP through inline Condition Rules. That is arbitrary code execution reachable by the lowest content-authoring role on a Joomla site, which on any site permitting self-registration with authoring rights means an attacker can create that account themselves. 8.0.0 restricts it and is flagged by the vendor as a BC BREAK, so sites legitimately using PHP in Condition Rules must re-authorise the author groups allowed to do so. CVE-2026-85188 is a shared-code defect: the same Condition Set implementation ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. Update to 8.0.0 or later and review who holds content-authoring rights. The CVE records were published on 14 September 2026: CVE-2026-85192 at CVSS 4.0 9.4 (Critical), vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H; CVE-2026-85188 at CVSS 4.0 6.9 (Medium), vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Conditional Content</category><category>Critical</category></item><item><title>CVE-2026-85191 - Tabs &amp; Accordions (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85191/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-85191/</guid><description>Regular Labs Tabs &amp; Accordions 3.0.0 through 3.0.5 is affected by CVE-2026-85191, fixed in 3.1.0 (released 13 September 2026). Crafted data-rlta-alias attributes were not sanitised, so JavaScript ran when a matching link was clicked. Exploitation requires the ability to author or edit content containing a Tabs &amp; Accordions link, so this is an authenticated stored XSS that fires on visitor interaction rather than on page load. Update to 3.1.0 or later. The CVE record was published on 14 September 2026 with a CVSS 4.0 base score of 7.5 (High), vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Tabs &amp; Accordions</category><category>High</category></item><item><title>CVE-2026-85190 - Quick Index (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85190/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-85190/</guid><description>Regular Labs Quick Index 5.0.0 through 5.0.4 is affected by CVE-2026-85190, fixed in 5.0.5 (released 13 September 2026). Crafted index class options were not sanitised, allowing JavaScript to be injected into the rendered index. Exploitation requires the ability to author or edit content containing a Quick Index tag, so this is an authenticated stored XSS. Update to 5.0.5 or later. The same release also fixes indexes showing headings from articles the visitor cannot access, an access control defect the vendor did not label a security fix but which discloses restricted article titles to unauthorised visitors. The CVE record was published on 14 September 2026 with a CVSS 4.0 base score of 7.5 (High), vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Quick Index</category><category>High</category></item><item><title>CVE-2026-85189 - Modals (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85189/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-85189/</guid><description>Regular Labs Modals 16.0.0 through 16.2.0 is affected by two vendor-confirmed security defects, both fixed in 17.0.0 (released 13 September 2026). CVE-2026-85189: modal links accepted javascript: URLs, so a crafted link executed script when the modal was opened. CVE-2026-88853: JavaScript Events could be attached by any user able to author content; 17.0.0 restricts them to selected article author groups by default. Both require the ability to author or edit content containing Modals links or tags, making this an authenticated stored XSS. Update to 17.0.0 or later. Note that 17.0.0 is flagged by the vendor as a BC BREAK: the JavaScript Events restriction is enabled by default and has to be re-opened deliberately per author group, so review those settings after updating. The CVE records were published on 14 September 2026: CVE-2026-85189 at CVSS 4.0 7.5 (High), vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N; CVE-2026-88853 at CVSS 4.0 7.5 (High), vector CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N/S:N/AU:N.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Modals</category><category>High</category></item><item><title>CVE-2026-85188 - Content Templater, Advanced Module Manager, ReReplacer, Conditional Content (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-85188/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-85188/</guid><description>Regular Labs Content Templater 14.0.0 through 14.1.0 is affected by CVE-2026-85188, fixed in 14.2.0 (released 13 September 2026). Condition Set labels could be made to reference unrelated database fields, disclosing data the operator was not entitled to read. The same Condition Set code ships in Advanced Module Manager, Conditional Content, Content Templater and ReReplacer, and Regular Labs fixed all four on 13 September 2026. Exploitation requires administrator access to create or edit a Condition Set, so this is an authenticated information disclosure rather than a remote one. Update to 14.2.0 or later. The same release also adds settings restricting who may save PHP Condition Rules, and fixes Condition Set saves not respecting publication and linked-item edit permissions. The CVE record was published on 14 September 2026 with a CVSS 4.0 base score of 6.9 (Medium), vector CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N.</description><pubDate>Sun, 13 Sep 2026 00:00:00 GMT</pubDate><category>Content Templater</category><category>Advanced Module Manager</category><category>ReReplacer</category><category>Conditional Content</category><category>Critical</category></item><item><title>CVE-2026-78303 - SP Property Finder (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78303/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78303/</guid><description>SP Property Finder below 4.1.4 contains an unauthenticated blind SQL injection in the public property search and map views, found by mySites.guru and reported privately to JoomShaper on 10 August 2026. Several search filters (the postcode, the sort control, and the price and size range dropdowns) are placed straight into the database query with no quoting, so an anonymous visitor with no login and no token can read any table in the Joomla database, password hashes and the site secret included. The injection is read-only, but reading the session table lets an attacker steal a logged-in administrator&apos;s session and take over the site from there, so treat it as serious. A second, lower-severity issue let the property contact and enquiry forms send email to any recipient with a spoofed sender (an unauthenticated mail relay). JoomShaper fixed both in SP Property Finder 4.1.4, released on 10 September 2026, which quotes and casts every filter value, validates the sort control against an allow-list, and derives the mail recipient from a database lookup instead of the request. mySites.guru verified the fix against the build JoomShaper shipped as 4.1.4. The same release also fixed further issues that mySites.guru did not report, tracked as CVE-2026-78084, CVE-2026-78302 and CVE-2026-78303. The reporter&apos;s two findings are CVE-2026-78082 (the SQL injection, published by the Joomla CNA at 9.3 Critical and credited to Phil Taylor of mySites.guru) and CVE-2026-78303 (the mail relay). The release also fixed CVE-2026-78083, CVE-2026-78084 and CVE-2026-78302, which mySites.guru did not report. All five CVE records were published at MITRE on 10 September 2026. Update to SP Property Finder 4.1.4 or later from JoomShaper. Updating closes the flaw but does not undo any database read that already happened: if a vulnerable version was public for a while, treat the password hashes and the site secret as potentially known.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>SP Property Finder</category><category>Critical</category></item><item><title>CVE-2026-78302 - SP Property Finder (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78302/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78302/</guid><description>SP Property Finder below 4.1.4 contains an unauthenticated blind SQL injection in the public property search and map views, found by mySites.guru and reported privately to JoomShaper on 10 August 2026. Several search filters (the postcode, the sort control, and the price and size range dropdowns) are placed straight into the database query with no quoting, so an anonymous visitor with no login and no token can read any table in the Joomla database, password hashes and the site secret included. The injection is read-only, but reading the session table lets an attacker steal a logged-in administrator&apos;s session and take over the site from there, so treat it as serious. A second, lower-severity issue let the property contact and enquiry forms send email to any recipient with a spoofed sender (an unauthenticated mail relay). JoomShaper fixed both in SP Property Finder 4.1.4, released on 10 September 2026, which quotes and casts every filter value, validates the sort control against an allow-list, and derives the mail recipient from a database lookup instead of the request. mySites.guru verified the fix against the build JoomShaper shipped as 4.1.4. The same release also fixed further issues that mySites.guru did not report, tracked as CVE-2026-78084, CVE-2026-78302 and CVE-2026-78303. The reporter&apos;s two findings are CVE-2026-78082 (the SQL injection, published by the Joomla CNA at 9.3 Critical and credited to Phil Taylor of mySites.guru) and CVE-2026-78303 (the mail relay). The release also fixed CVE-2026-78083, CVE-2026-78084 and CVE-2026-78302, which mySites.guru did not report. All five CVE records were published at MITRE on 10 September 2026. Update to SP Property Finder 4.1.4 or later from JoomShaper. Updating closes the flaw but does not undo any database read that already happened: if a vulnerable version was public for a while, treat the password hashes and the site secret as potentially known.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>SP Property Finder</category><category>Critical</category></item><item><title>CVE-2026-78085 - SP Property Finder (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78085/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78085/</guid><description>SP Property Finder below 4.1.4 contains an unauthenticated blind SQL injection in the public property search and map views, found by mySites.guru and reported privately to JoomShaper on 10 August 2026. Several search filters (the postcode, the sort control, and the price and size range dropdowns) are placed straight into the database query with no quoting, so an anonymous visitor with no login and no token can read any table in the Joomla database, password hashes and the site secret included. The injection is read-only, but reading the session table lets an attacker steal a logged-in administrator&apos;s session and take over the site from there, so treat it as serious. A second, lower-severity issue let the property contact and enquiry forms send email to any recipient with a spoofed sender (an unauthenticated mail relay). JoomShaper fixed both in SP Property Finder 4.1.4, released on 10 September 2026, which quotes and casts every filter value, validates the sort control against an allow-list, and derives the mail recipient from a database lookup instead of the request. mySites.guru verified the fix against the build JoomShaper shipped as 4.1.4. The same release also fixed further issues that mySites.guru did not report, tracked as CVE-2026-78084, CVE-2026-78302 and CVE-2026-78303. The reporter&apos;s two findings are CVE-2026-78082 (the SQL injection, published by the Joomla CNA at 9.3 Critical and credited to Phil Taylor of mySites.guru) and CVE-2026-78303 (the mail relay). The release also fixed CVE-2026-78083, CVE-2026-78084 and CVE-2026-78302, which mySites.guru did not report. All five CVE records were published at MITRE on 10 September 2026. Update to SP Property Finder 4.1.4 or later from JoomShaper. Updating closes the flaw but does not undo any database read that already happened: if a vulnerable version was public for a while, treat the password hashes and the site secret as potentially known.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>SP Property Finder</category><category>Critical</category></item><item><title>CVE-2026-78084 - SP Property Finder (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78084/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78084/</guid><description>SP Property Finder below 4.1.4 contains an unauthenticated blind SQL injection in the public property search and map views, found by mySites.guru and reported privately to JoomShaper on 10 August 2026. Several search filters (the postcode, the sort control, and the price and size range dropdowns) are placed straight into the database query with no quoting, so an anonymous visitor with no login and no token can read any table in the Joomla database, password hashes and the site secret included. The injection is read-only, but reading the session table lets an attacker steal a logged-in administrator&apos;s session and take over the site from there, so treat it as serious. A second, lower-severity issue let the property contact and enquiry forms send email to any recipient with a spoofed sender (an unauthenticated mail relay). JoomShaper fixed both in SP Property Finder 4.1.4, released on 10 September 2026, which quotes and casts every filter value, validates the sort control against an allow-list, and derives the mail recipient from a database lookup instead of the request. mySites.guru verified the fix against the build JoomShaper shipped as 4.1.4. The same release also fixed further issues that mySites.guru did not report, tracked as CVE-2026-78084, CVE-2026-78302 and CVE-2026-78303. The reporter&apos;s two findings are CVE-2026-78082 (the SQL injection, published by the Joomla CNA at 9.3 Critical and credited to Phil Taylor of mySites.guru) and CVE-2026-78303 (the mail relay). The release also fixed CVE-2026-78083, CVE-2026-78084 and CVE-2026-78302, which mySites.guru did not report. All five CVE records were published at MITRE on 10 September 2026. Update to SP Property Finder 4.1.4 or later from JoomShaper. Updating closes the flaw but does not undo any database read that already happened: if a vulnerable version was public for a while, treat the password hashes and the site secret as potentially known.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>SP Property Finder</category><category>Critical</category></item><item><title>CVE-2026-78083 - SP Property Finder (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78083/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78083/</guid><description>SP Property Finder below 4.1.4 contains an unauthenticated blind SQL injection in the public property search and map views, found by mySites.guru and reported privately to JoomShaper on 10 August 2026. Several search filters (the postcode, the sort control, and the price and size range dropdowns) are placed straight into the database query with no quoting, so an anonymous visitor with no login and no token can read any table in the Joomla database, password hashes and the site secret included. The injection is read-only, but reading the session table lets an attacker steal a logged-in administrator&apos;s session and take over the site from there, so treat it as serious. A second, lower-severity issue let the property contact and enquiry forms send email to any recipient with a spoofed sender (an unauthenticated mail relay). JoomShaper fixed both in SP Property Finder 4.1.4, released on 10 September 2026, which quotes and casts every filter value, validates the sort control against an allow-list, and derives the mail recipient from a database lookup instead of the request. mySites.guru verified the fix against the build JoomShaper shipped as 4.1.4. The same release also fixed further issues that mySites.guru did not report, tracked as CVE-2026-78084, CVE-2026-78302 and CVE-2026-78303. The reporter&apos;s two findings are CVE-2026-78082 (the SQL injection, published by the Joomla CNA at 9.3 Critical and credited to Phil Taylor of mySites.guru) and CVE-2026-78303 (the mail relay). The release also fixed CVE-2026-78083, CVE-2026-78084 and CVE-2026-78302, which mySites.guru did not report. All five CVE records were published at MITRE on 10 September 2026. Update to SP Property Finder 4.1.4 or later from JoomShaper. Updating closes the flaw but does not undo any database read that already happened: if a vulnerable version was public for a while, treat the password hashes and the site secret as potentially known.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>SP Property Finder</category><category>Critical</category></item><item><title>CVE-2026-78082 - SP Property Finder (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78082/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78082/</guid><description>SP Property Finder below 4.1.4 contains an unauthenticated blind SQL injection in the public property search and map views, found by mySites.guru and reported privately to JoomShaper on 10 August 2026. Several search filters (the postcode, the sort control, and the price and size range dropdowns) are placed straight into the database query with no quoting, so an anonymous visitor with no login and no token can read any table in the Joomla database, password hashes and the site secret included. The injection is read-only, but reading the session table lets an attacker steal a logged-in administrator&apos;s session and take over the site from there, so treat it as serious. A second, lower-severity issue let the property contact and enquiry forms send email to any recipient with a spoofed sender (an unauthenticated mail relay). JoomShaper fixed both in SP Property Finder 4.1.4, released on 10 September 2026, which quotes and casts every filter value, validates the sort control against an allow-list, and derives the mail recipient from a database lookup instead of the request. mySites.guru verified the fix against the build JoomShaper shipped as 4.1.4. The same release also fixed further issues that mySites.guru did not report, tracked as CVE-2026-78084, CVE-2026-78302 and CVE-2026-78303. The reporter&apos;s two findings are CVE-2026-78082 (the SQL injection, published by the Joomla CNA at 9.3 Critical and credited to Phil Taylor of mySites.guru) and CVE-2026-78303 (the mail relay). The release also fixed CVE-2026-78083, CVE-2026-78084 and CVE-2026-78302, which mySites.guru did not report. All five CVE records were published at MITRE on 10 September 2026. Update to SP Property Finder 4.1.4 or later from JoomShaper. Updating closes the flaw but does not undo any database read that already happened: if a vulnerable version was public for a while, treat the password hashes and the site secret as potentially known.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><category>SP Property Finder</category><category>Critical</category></item><item><title>CVE-2026-78080 - JooDatabase (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78080/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78080/</guid><description>JooDatabase versions before 5.1 pass the front-end cid request parameter straight into a SQL WHERE clause without escaping it. The catalog view reads cid from the request and interpolates each value raw, so an anonymous visitor needs no account, no token and no user interaction to inject arbitrary SQL and read anything the site database holds, including the Joomla user table and its password hashes. CVSS 9.3 Critical (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H), CWE-89. Found by Krzysztof Zajac of CERT PL. Joomla 4, 5 and 6: update to JooDatabase 5.1, released 3 September 2026. The vendor update stream does serve this release to Joomla 4, 5 and 6, so it appears in the normal Update your extensions screen. It can also be installed by hand from https://joodb.feenders.de/index.php/download. Joomla 3 has no fix, and the Joomla backend will not tell those site owners that. The vendor Joomla 3 branch is still com_joodb-3x.zip version 3.2 from May 2022, and its models/catalog.php contains the same unescaped cid interpolation, so it is vulnerable too. The vendor update stream offers Joomla 3 sites only a 3.2.0 block, which is lower than most builds people actually run, so a Joomla 3 site sitting on 3.2.1, 3.6.1, 3.9.x or 3.13 is offered nothing at all and reads as up to date forever, while a site on 3.2 or older is offered an update that still contains the bug. Either way the backend is not a reliable signal here. Those sites are stranded rather than behind: the real remediation is migrating to Joomla 4 or later and installing JooDatabase 5.1. Until then, unpublish or uninstall the component, or block the front-end catalog view at the web server or WAF. Note on the CVE wording: the record names the product JooDatabase Lite, but the vendor stopped shipping separate Lite and Pro editions at the start of 2022 and everything since is a single free release, so this applies to any JooDatabase install in range. The CVE structured version list also states 1.0-5.0.0 while its own title and description say below 5.1.0. The vendor release and the shipped code resolve that in favour of below 5.1: the 5.1 zip served by the update stream carries the db-&gt;quote fix, and the 5.0.2 build that preceded it still has the raw interpolation, so 5.0.1 and 5.0.2 are vulnerable.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><category>JooDatabase</category><category>Critical</category></item><item><title>CVE-2026-78079 - Helix Ultimate Framework, Helix Ultimate (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78079/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78079/</guid><description>JoomShaper released Helix Ultimate 2.2.10 on 27 August 2026 as a security update, and states that all versions prior to 2.2.10 are affected. It grades the issues High / Medium. The fixes in this release are: strict com_media permission enforcement (core.manage, core.create, core.delete) across every media AJAX endpoint; binary raster and MIME content verification on image uploads to block upload filter bypasses; canonical realpath validation and null-byte detection on media path resolution (path traversal); draft cache path manipulation blocked by deriving template style identity from verified database records; Live Preview and Coming Soon bypass restricted to authenticated users holding template edit rights; object-level authorization and ownership checks before frontend article attributes are saved; edit permission and item validation on Mega Menu configuration; sanitisation of Mega Menu modal JSON layout settings against XSS; strict heading tag, CSS colour format and attribute validation in the Page Title feature; hardened social sharing URL generation and JavaScript handlers; strict identifier validation and output encoding on video and audio embeds; escaped image source URLs in legacy image layout overrides. The Joomla CNA published five CVEs for this release on 31 August 2026, every one of them with the affected range 1.0-2.2.9: CVE-2026-78078 (8.9 High, privileged file upload bypass via content spoofing - upload validation checked only the file extension and basic size, so a non-image disguised with a raster extension was accepted; 2.2.10 adds strict MIME verification and GD binary raster decoding that fails closed), CVE-2026-78077 (8.6 High, stored XSS in the Mega Menu layout container and embed inputs - unsanitised column and item configuration values held in the Mega Menu layout JSON were rendered without complete contextual escaping), CVE-2026-78079 (5.3 Medium, open redirect - the return redirect parameter accepted any Base64 string without checking the resolved target with Uri::isInternal), CVE-2026-78075 (5.1 Medium, broken object-level authorization in Blog::remove_image - the check validated the article id passed in the request but never confirmed that the supplied image path belonged to that article, letting an author delete arbitrary files under /images/; reported by Phil Taylor of mySites.guru) and CVE-2026-78076 (5.1 Medium, missing item-level and menu-level authorization on the save-megamenu-settings AJAX endpoint, so an authenticated user could rewrite layout parameters for arbitrary menu items). Four of the five score PR:H and need an authenticated, privileged account; only the open redirect (CVE-2026-78079) is PR:N, and that one also needs user interaction. So the original judgement stands: this is not an unauthenticated remote attack surface, unlike CVE-2026-57829 / CVE-2026-57830 below. One trap when reading the CNA records: CVE-2026-78079 is TITLED &apos;Privileged File Upload Bypass via Content Spoofing&apos;, a straight duplicate of CVE-2026-78078&apos;s title, while its description and its CVSS vector are the open redirect. The description is the correct half. This is the same component and the same Mega Menu surface as CVE-2026-57829 and CVE-2026-57830, which were exploited in the wild in July 2026, so treat it as urgent. Action: update Helix Ultimate to 2.2.10 or later. Note this rule covers the plugin (System - Helix Ultimate Framework); the shaper_helixultimate TEMPLATE is a separate install that does not appear in Joomla Updates and must be upgraded manually. Joomla 3 sites cannot install 2.2.10 - JoomShaper ships a separate J3 security patch (helixultimate_j3_security_fixes, currently v1.0.3, released 31 August 2026) which leaves the reported extension version at 2.1.4-j3sec, so a J3 install gives no version evidence of its patch level and is deliberately outside this range.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>Helix Ultimate Framework</category><category>Helix Ultimate</category><category>High</category></item><item><title>CVE-2026-78078 - Helix Ultimate Framework, Helix Ultimate (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78078/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78078/</guid><description>JoomShaper released Helix Ultimate 2.2.10 on 27 August 2026 as a security update, and states that all versions prior to 2.2.10 are affected. It grades the issues High / Medium. The fixes in this release are: strict com_media permission enforcement (core.manage, core.create, core.delete) across every media AJAX endpoint; binary raster and MIME content verification on image uploads to block upload filter bypasses; canonical realpath validation and null-byte detection on media path resolution (path traversal); draft cache path manipulation blocked by deriving template style identity from verified database records; Live Preview and Coming Soon bypass restricted to authenticated users holding template edit rights; object-level authorization and ownership checks before frontend article attributes are saved; edit permission and item validation on Mega Menu configuration; sanitisation of Mega Menu modal JSON layout settings against XSS; strict heading tag, CSS colour format and attribute validation in the Page Title feature; hardened social sharing URL generation and JavaScript handlers; strict identifier validation and output encoding on video and audio embeds; escaped image source URLs in legacy image layout overrides. The Joomla CNA published five CVEs for this release on 31 August 2026, every one of them with the affected range 1.0-2.2.9: CVE-2026-78078 (8.9 High, privileged file upload bypass via content spoofing - upload validation checked only the file extension and basic size, so a non-image disguised with a raster extension was accepted; 2.2.10 adds strict MIME verification and GD binary raster decoding that fails closed), CVE-2026-78077 (8.6 High, stored XSS in the Mega Menu layout container and embed inputs - unsanitised column and item configuration values held in the Mega Menu layout JSON were rendered without complete contextual escaping), CVE-2026-78079 (5.3 Medium, open redirect - the return redirect parameter accepted any Base64 string without checking the resolved target with Uri::isInternal), CVE-2026-78075 (5.1 Medium, broken object-level authorization in Blog::remove_image - the check validated the article id passed in the request but never confirmed that the supplied image path belonged to that article, letting an author delete arbitrary files under /images/; reported by Phil Taylor of mySites.guru) and CVE-2026-78076 (5.1 Medium, missing item-level and menu-level authorization on the save-megamenu-settings AJAX endpoint, so an authenticated user could rewrite layout parameters for arbitrary menu items). Four of the five score PR:H and need an authenticated, privileged account; only the open redirect (CVE-2026-78079) is PR:N, and that one also needs user interaction. So the original judgement stands: this is not an unauthenticated remote attack surface, unlike CVE-2026-57829 / CVE-2026-57830 below. One trap when reading the CNA records: CVE-2026-78079 is TITLED &apos;Privileged File Upload Bypass via Content Spoofing&apos;, a straight duplicate of CVE-2026-78078&apos;s title, while its description and its CVSS vector are the open redirect. The description is the correct half. This is the same component and the same Mega Menu surface as CVE-2026-57829 and CVE-2026-57830, which were exploited in the wild in July 2026, so treat it as urgent. Action: update Helix Ultimate to 2.2.10 or later. Note this rule covers the plugin (System - Helix Ultimate Framework); the shaper_helixultimate TEMPLATE is a separate install that does not appear in Joomla Updates and must be upgraded manually. Joomla 3 sites cannot install 2.2.10 - JoomShaper ships a separate J3 security patch (helixultimate_j3_security_fixes, currently v1.0.3, released 31 August 2026) which leaves the reported extension version at 2.1.4-j3sec, so a J3 install gives no version evidence of its patch level and is deliberately outside this range.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>Helix Ultimate Framework</category><category>Helix Ultimate</category><category>High</category></item><item><title>CVE-2026-78077 - Helix Ultimate Framework, Helix Ultimate (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78077/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78077/</guid><description>JoomShaper released Helix Ultimate 2.2.10 on 27 August 2026 as a security update, and states that all versions prior to 2.2.10 are affected. It grades the issues High / Medium. The fixes in this release are: strict com_media permission enforcement (core.manage, core.create, core.delete) across every media AJAX endpoint; binary raster and MIME content verification on image uploads to block upload filter bypasses; canonical realpath validation and null-byte detection on media path resolution (path traversal); draft cache path manipulation blocked by deriving template style identity from verified database records; Live Preview and Coming Soon bypass restricted to authenticated users holding template edit rights; object-level authorization and ownership checks before frontend article attributes are saved; edit permission and item validation on Mega Menu configuration; sanitisation of Mega Menu modal JSON layout settings against XSS; strict heading tag, CSS colour format and attribute validation in the Page Title feature; hardened social sharing URL generation and JavaScript handlers; strict identifier validation and output encoding on video and audio embeds; escaped image source URLs in legacy image layout overrides. The Joomla CNA published five CVEs for this release on 31 August 2026, every one of them with the affected range 1.0-2.2.9: CVE-2026-78078 (8.9 High, privileged file upload bypass via content spoofing - upload validation checked only the file extension and basic size, so a non-image disguised with a raster extension was accepted; 2.2.10 adds strict MIME verification and GD binary raster decoding that fails closed), CVE-2026-78077 (8.6 High, stored XSS in the Mega Menu layout container and embed inputs - unsanitised column and item configuration values held in the Mega Menu layout JSON were rendered without complete contextual escaping), CVE-2026-78079 (5.3 Medium, open redirect - the return redirect parameter accepted any Base64 string without checking the resolved target with Uri::isInternal), CVE-2026-78075 (5.1 Medium, broken object-level authorization in Blog::remove_image - the check validated the article id passed in the request but never confirmed that the supplied image path belonged to that article, letting an author delete arbitrary files under /images/; reported by Phil Taylor of mySites.guru) and CVE-2026-78076 (5.1 Medium, missing item-level and menu-level authorization on the save-megamenu-settings AJAX endpoint, so an authenticated user could rewrite layout parameters for arbitrary menu items). Four of the five score PR:H and need an authenticated, privileged account; only the open redirect (CVE-2026-78079) is PR:N, and that one also needs user interaction. So the original judgement stands: this is not an unauthenticated remote attack surface, unlike CVE-2026-57829 / CVE-2026-57830 below. One trap when reading the CNA records: CVE-2026-78079 is TITLED &apos;Privileged File Upload Bypass via Content Spoofing&apos;, a straight duplicate of CVE-2026-78078&apos;s title, while its description and its CVSS vector are the open redirect. The description is the correct half. This is the same component and the same Mega Menu surface as CVE-2026-57829 and CVE-2026-57830, which were exploited in the wild in July 2026, so treat it as urgent. Action: update Helix Ultimate to 2.2.10 or later. Note this rule covers the plugin (System - Helix Ultimate Framework); the shaper_helixultimate TEMPLATE is a separate install that does not appear in Joomla Updates and must be upgraded manually. Joomla 3 sites cannot install 2.2.10 - JoomShaper ships a separate J3 security patch (helixultimate_j3_security_fixes, currently v1.0.3, released 31 August 2026) which leaves the reported extension version at 2.1.4-j3sec, so a J3 install gives no version evidence of its patch level and is deliberately outside this range.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>Helix Ultimate Framework</category><category>Helix Ultimate</category><category>High</category></item><item><title>CVE-2026-78076 - Helix Ultimate Framework, Helix Ultimate (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78076/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78076/</guid><description>JoomShaper released Helix Ultimate 2.2.10 on 27 August 2026 as a security update, and states that all versions prior to 2.2.10 are affected. It grades the issues High / Medium. The fixes in this release are: strict com_media permission enforcement (core.manage, core.create, core.delete) across every media AJAX endpoint; binary raster and MIME content verification on image uploads to block upload filter bypasses; canonical realpath validation and null-byte detection on media path resolution (path traversal); draft cache path manipulation blocked by deriving template style identity from verified database records; Live Preview and Coming Soon bypass restricted to authenticated users holding template edit rights; object-level authorization and ownership checks before frontend article attributes are saved; edit permission and item validation on Mega Menu configuration; sanitisation of Mega Menu modal JSON layout settings against XSS; strict heading tag, CSS colour format and attribute validation in the Page Title feature; hardened social sharing URL generation and JavaScript handlers; strict identifier validation and output encoding on video and audio embeds; escaped image source URLs in legacy image layout overrides. The Joomla CNA published five CVEs for this release on 31 August 2026, every one of them with the affected range 1.0-2.2.9: CVE-2026-78078 (8.9 High, privileged file upload bypass via content spoofing - upload validation checked only the file extension and basic size, so a non-image disguised with a raster extension was accepted; 2.2.10 adds strict MIME verification and GD binary raster decoding that fails closed), CVE-2026-78077 (8.6 High, stored XSS in the Mega Menu layout container and embed inputs - unsanitised column and item configuration values held in the Mega Menu layout JSON were rendered without complete contextual escaping), CVE-2026-78079 (5.3 Medium, open redirect - the return redirect parameter accepted any Base64 string without checking the resolved target with Uri::isInternal), CVE-2026-78075 (5.1 Medium, broken object-level authorization in Blog::remove_image - the check validated the article id passed in the request but never confirmed that the supplied image path belonged to that article, letting an author delete arbitrary files under /images/; reported by Phil Taylor of mySites.guru) and CVE-2026-78076 (5.1 Medium, missing item-level and menu-level authorization on the save-megamenu-settings AJAX endpoint, so an authenticated user could rewrite layout parameters for arbitrary menu items). Four of the five score PR:H and need an authenticated, privileged account; only the open redirect (CVE-2026-78079) is PR:N, and that one also needs user interaction. So the original judgement stands: this is not an unauthenticated remote attack surface, unlike CVE-2026-57829 / CVE-2026-57830 below. One trap when reading the CNA records: CVE-2026-78079 is TITLED &apos;Privileged File Upload Bypass via Content Spoofing&apos;, a straight duplicate of CVE-2026-78078&apos;s title, while its description and its CVSS vector are the open redirect. The description is the correct half. This is the same component and the same Mega Menu surface as CVE-2026-57829 and CVE-2026-57830, which were exploited in the wild in July 2026, so treat it as urgent. Action: update Helix Ultimate to 2.2.10 or later. Note this rule covers the plugin (System - Helix Ultimate Framework); the shaper_helixultimate TEMPLATE is a separate install that does not appear in Joomla Updates and must be upgraded manually. Joomla 3 sites cannot install 2.2.10 - JoomShaper ships a separate J3 security patch (helixultimate_j3_security_fixes, currently v1.0.3, released 31 August 2026) which leaves the reported extension version at 2.1.4-j3sec, so a J3 install gives no version evidence of its patch level and is deliberately outside this range.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>Helix Ultimate Framework</category><category>Helix Ultimate</category><category>High</category></item><item><title>CVE-2026-78075 - Helix Ultimate Framework, Helix Ultimate (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78075/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78075/</guid><description>JoomShaper released Helix Ultimate 2.2.10 on 27 August 2026 as a security update, and states that all versions prior to 2.2.10 are affected. It grades the issues High / Medium. The fixes in this release are: strict com_media permission enforcement (core.manage, core.create, core.delete) across every media AJAX endpoint; binary raster and MIME content verification on image uploads to block upload filter bypasses; canonical realpath validation and null-byte detection on media path resolution (path traversal); draft cache path manipulation blocked by deriving template style identity from verified database records; Live Preview and Coming Soon bypass restricted to authenticated users holding template edit rights; object-level authorization and ownership checks before frontend article attributes are saved; edit permission and item validation on Mega Menu configuration; sanitisation of Mega Menu modal JSON layout settings against XSS; strict heading tag, CSS colour format and attribute validation in the Page Title feature; hardened social sharing URL generation and JavaScript handlers; strict identifier validation and output encoding on video and audio embeds; escaped image source URLs in legacy image layout overrides. The Joomla CNA published five CVEs for this release on 31 August 2026, every one of them with the affected range 1.0-2.2.9: CVE-2026-78078 (8.9 High, privileged file upload bypass via content spoofing - upload validation checked only the file extension and basic size, so a non-image disguised with a raster extension was accepted; 2.2.10 adds strict MIME verification and GD binary raster decoding that fails closed), CVE-2026-78077 (8.6 High, stored XSS in the Mega Menu layout container and embed inputs - unsanitised column and item configuration values held in the Mega Menu layout JSON were rendered without complete contextual escaping), CVE-2026-78079 (5.3 Medium, open redirect - the return redirect parameter accepted any Base64 string without checking the resolved target with Uri::isInternal), CVE-2026-78075 (5.1 Medium, broken object-level authorization in Blog::remove_image - the check validated the article id passed in the request but never confirmed that the supplied image path belonged to that article, letting an author delete arbitrary files under /images/; reported by Phil Taylor of mySites.guru) and CVE-2026-78076 (5.1 Medium, missing item-level and menu-level authorization on the save-megamenu-settings AJAX endpoint, so an authenticated user could rewrite layout parameters for arbitrary menu items). Four of the five score PR:H and need an authenticated, privileged account; only the open redirect (CVE-2026-78079) is PR:N, and that one also needs user interaction. So the original judgement stands: this is not an unauthenticated remote attack surface, unlike CVE-2026-57829 / CVE-2026-57830 below. One trap when reading the CNA records: CVE-2026-78079 is TITLED &apos;Privileged File Upload Bypass via Content Spoofing&apos;, a straight duplicate of CVE-2026-78078&apos;s title, while its description and its CVSS vector are the open redirect. The description is the correct half. This is the same component and the same Mega Menu surface as CVE-2026-57829 and CVE-2026-57830, which were exploited in the wild in July 2026, so treat it as urgent. Action: update Helix Ultimate to 2.2.10 or later. Note this rule covers the plugin (System - Helix Ultimate Framework); the shaper_helixultimate TEMPLATE is a separate install that does not appear in Joomla Updates and must be upgraded manually. Joomla 3 sites cannot install 2.2.10 - JoomShaper ships a separate J3 security patch (helixultimate_j3_security_fixes, currently v1.0.3, released 31 August 2026) which leaves the reported extension version at 2.1.4-j3sec, so a J3 install gives no version evidence of its patch level and is deliberately outside this range.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>Helix Ultimate Framework</category><category>Helix Ultimate</category><category>High</category></item><item><title>CVE-2026-78074 - miniOrange SAML SSO, miniOrange OAuth Client, miniOrange LDAP Integration, miniOrange Custom API, miniOrange Import Export Users, miniOrange Keycloak User Sync, miniOrange Restrict Files / Folders, miniOrange SCIM User Provisioning, miniOrange Two Factor Authentication (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78074/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78074/</guid><description>CERT PL (Krzysztof Zajac) reported that a large set of miniOrange Joomla extensions expose an endpoint with a missing authentication check, letting an unauthenticated attacker uninstall any extension installed on the site (CWE-284 Improper Access Control, CVSS 4.0 base score 8.8 High, AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:H). Uninstalling an extension takes its functionality offline and, on most Joomla extensions, runs its uninstall script and drops its database tables, so this is a remote, unauthenticated, destructive denial of service that can be pointed at any component, module or plugin on the site - security and login extensions included. There is no confidentiality impact: the attacker deletes, it does not read. CVE-2026-78074 names 23 miniOrange Joomla extensions and states explicitly that ONLY THE FREE editions are affected. This rule covers one of them, &quot;SAML SSO for Joomla (free)&quot;, at the CVE&apos;s stated affected range 1.0.0-11.0.2. miniOrange numbers its paid editions in decades on the same element (builds such as 12.x, 21.x, 22.x, 32.x, 34.x and 44.x are in the wild on these components), and those sit above this ceiling, so they are deliberately not flagged - consistent with the CVE limiting the flaw to the free editions. FIXED: update miniOrange SAML SSO for Joomla to 11.0.3 or later. miniOrange released the fix on 31 August 2026. This was verified independently of the vendor&apos;s own claim: the Joomla Extensions Directory listing for this extension shows 11.0.3 with that release date. Connected sites have already been observed reporting 11.0.3. This rule&apos;s upper bound is the last version known to be AFFECTED, not the fix version, so any site inside the range still needs the update. If you cannot update immediately, uninstall the extension where it is not actually in use, and otherwise block unauthenticated access to the component&apos;s endpoints at the web application firewall or web server.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>miniOrange SAML SSO</category><category>miniOrange OAuth Client</category><category>miniOrange LDAP Integration</category><category>miniOrange Custom API</category><category>miniOrange Import Export Users</category><category>miniOrange Keycloak User Sync</category><category>miniOrange Restrict Files / Folders</category><category>miniOrange SCIM User Provisioning</category><category>miniOrange Two Factor Authentication</category><category>High</category></item><item><title>CVE-2026-78069 - J2Store / J2Commerce (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78069/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78069/</guid><description>J2Store 3.3.21 on the Joomla 3 branch is affected by five vulnerabilities in com_j2store, disclosed by Phil Taylor (mySites.guru) and fixed by J2Commerce on 31 August 2026. CVE-2026-78069 (CVSS 9.5, Critical): the administrator Apps controller instantiates app-plugin controllers through an appTask delegation path with no com_j2store ACL check anywhere in the code, and the backend node of fof.xml declares no view ACL at all, so FOF defaults an unmatched task to allow rather than deny. Any authenticated Joomla backend user, holding no J2Store permission whatsoever, can trigger #__j2store_* table truncation and traversal-based SQL file execution; only the Joomla core administrator login wall keeps anonymous visitors out, and that checks nothing about com_j2store permissions. CVE-2026-78064 (CVSS 8.8, High): the carts view inherits the generic FOF save task under a wildcard true ACL in fof.xml, and FOF enforces CSRF tokens only on backend HTML requests, not on frontend format=raw requests, so an unauthenticated POST can insert cart rows with an attacker-chosen user_id or session_id, or overwrite an existing row by id. CVE-2026-77999 (CVSS 8.7, High): the PayPal IPN listener treated UNVERIFIED and any non-INVALID response as valid, made its verification request with CURLOPT_SSL_VERIFYPEER disabled, and stored the verdict in a field nothing downstream read, so processing continued regardless of the outcome; separately, omitting mc_gross from the POST body skipped the paid-amount comparison entirely. Unauthenticated requests could confirm orders that were never paid for, or fail legitimate ones. CVE-2026-78065 (CVSS 7.1, High): editAddress() redirected non-owners away only when the loaded address row had a non-empty user_id, and guest checkout rows have none, so any logged-in account guessing a small sequential address_id was shown a guest customer full name, street address and phone number prefilled into the edit form. CVE-2026-78000 (CVSS 5.3, Medium): filter_tag, pricefrom and priceto are echoed unescaped into a hidden input value attribute by J2Html::input(), across all six shipped product-tags templates, giving reflected XSS from a crafted link with no click beyond the initial navigation. FIX: update to 3.3.22 on this Joomla 3 branch (the equivalent fixes are 4.0.22 on 4.0.x and 4.1.7 on 4.1.x). If you cannot update immediately: disable PayPal, or watch pending orders for CONFIRMED or FAILED transitions with no matching PayPal transaction; disable guest checkout; and review every Joomla backend account regardless of privilege level, because the Apps controller issue needs a backend login but no J2Store permission. All five CVE records were published by the Joomla CNA on 3 September 2026 and all five credit Phil Taylor, mySites.guru. The affected ranges are unchanged. Four scores match the vendor advisory; CVE-2026-78069 was raised from the vendor&apos;s 9.4 to 9.5 Critical, and the published vector reads AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, scoring the backend login as an attack requirement (AT:P) rather than a privilege (PR:L).</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>J2Store / J2Commerce</category><category>Critical</category></item><item><title>CVE-2026-78065 - J2Store / J2Commerce (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78065/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78065/</guid><description>J2Store 3.3.21 on the Joomla 3 branch is affected by five vulnerabilities in com_j2store, disclosed by Phil Taylor (mySites.guru) and fixed by J2Commerce on 31 August 2026. CVE-2026-78069 (CVSS 9.5, Critical): the administrator Apps controller instantiates app-plugin controllers through an appTask delegation path with no com_j2store ACL check anywhere in the code, and the backend node of fof.xml declares no view ACL at all, so FOF defaults an unmatched task to allow rather than deny. Any authenticated Joomla backend user, holding no J2Store permission whatsoever, can trigger #__j2store_* table truncation and traversal-based SQL file execution; only the Joomla core administrator login wall keeps anonymous visitors out, and that checks nothing about com_j2store permissions. CVE-2026-78064 (CVSS 8.8, High): the carts view inherits the generic FOF save task under a wildcard true ACL in fof.xml, and FOF enforces CSRF tokens only on backend HTML requests, not on frontend format=raw requests, so an unauthenticated POST can insert cart rows with an attacker-chosen user_id or session_id, or overwrite an existing row by id. CVE-2026-77999 (CVSS 8.7, High): the PayPal IPN listener treated UNVERIFIED and any non-INVALID response as valid, made its verification request with CURLOPT_SSL_VERIFYPEER disabled, and stored the verdict in a field nothing downstream read, so processing continued regardless of the outcome; separately, omitting mc_gross from the POST body skipped the paid-amount comparison entirely. Unauthenticated requests could confirm orders that were never paid for, or fail legitimate ones. CVE-2026-78065 (CVSS 7.1, High): editAddress() redirected non-owners away only when the loaded address row had a non-empty user_id, and guest checkout rows have none, so any logged-in account guessing a small sequential address_id was shown a guest customer full name, street address and phone number prefilled into the edit form. CVE-2026-78000 (CVSS 5.3, Medium): filter_tag, pricefrom and priceto are echoed unescaped into a hidden input value attribute by J2Html::input(), across all six shipped product-tags templates, giving reflected XSS from a crafted link with no click beyond the initial navigation. FIX: update to 3.3.22 on this Joomla 3 branch (the equivalent fixes are 4.0.22 on 4.0.x and 4.1.7 on 4.1.x). If you cannot update immediately: disable PayPal, or watch pending orders for CONFIRMED or FAILED transitions with no matching PayPal transaction; disable guest checkout; and review every Joomla backend account regardless of privilege level, because the Apps controller issue needs a backend login but no J2Store permission. All five CVE records were published by the Joomla CNA on 3 September 2026 and all five credit Phil Taylor, mySites.guru. The affected ranges are unchanged. Four scores match the vendor advisory; CVE-2026-78069 was raised from the vendor&apos;s 9.4 to 9.5 Critical, and the published vector reads AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, scoring the backend login as an attack requirement (AT:P) rather than a privilege (PR:L).</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>J2Store / J2Commerce</category><category>Critical</category></item><item><title>CVE-2026-78064 - J2Store / J2Commerce (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78064/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78064/</guid><description>J2Store 3.3.21 on the Joomla 3 branch is affected by five vulnerabilities in com_j2store, disclosed by Phil Taylor (mySites.guru) and fixed by J2Commerce on 31 August 2026. CVE-2026-78069 (CVSS 9.5, Critical): the administrator Apps controller instantiates app-plugin controllers through an appTask delegation path with no com_j2store ACL check anywhere in the code, and the backend node of fof.xml declares no view ACL at all, so FOF defaults an unmatched task to allow rather than deny. Any authenticated Joomla backend user, holding no J2Store permission whatsoever, can trigger #__j2store_* table truncation and traversal-based SQL file execution; only the Joomla core administrator login wall keeps anonymous visitors out, and that checks nothing about com_j2store permissions. CVE-2026-78064 (CVSS 8.8, High): the carts view inherits the generic FOF save task under a wildcard true ACL in fof.xml, and FOF enforces CSRF tokens only on backend HTML requests, not on frontend format=raw requests, so an unauthenticated POST can insert cart rows with an attacker-chosen user_id or session_id, or overwrite an existing row by id. CVE-2026-77999 (CVSS 8.7, High): the PayPal IPN listener treated UNVERIFIED and any non-INVALID response as valid, made its verification request with CURLOPT_SSL_VERIFYPEER disabled, and stored the verdict in a field nothing downstream read, so processing continued regardless of the outcome; separately, omitting mc_gross from the POST body skipped the paid-amount comparison entirely. Unauthenticated requests could confirm orders that were never paid for, or fail legitimate ones. CVE-2026-78065 (CVSS 7.1, High): editAddress() redirected non-owners away only when the loaded address row had a non-empty user_id, and guest checkout rows have none, so any logged-in account guessing a small sequential address_id was shown a guest customer full name, street address and phone number prefilled into the edit form. CVE-2026-78000 (CVSS 5.3, Medium): filter_tag, pricefrom and priceto are echoed unescaped into a hidden input value attribute by J2Html::input(), across all six shipped product-tags templates, giving reflected XSS from a crafted link with no click beyond the initial navigation. FIX: update to 3.3.22 on this Joomla 3 branch (the equivalent fixes are 4.0.22 on 4.0.x and 4.1.7 on 4.1.x). If you cannot update immediately: disable PayPal, or watch pending orders for CONFIRMED or FAILED transitions with no matching PayPal transaction; disable guest checkout; and review every Joomla backend account regardless of privilege level, because the Apps controller issue needs a backend login but no J2Store permission. All five CVE records were published by the Joomla CNA on 3 September 2026 and all five credit Phil Taylor, mySites.guru. The affected ranges are unchanged. Four scores match the vendor advisory; CVE-2026-78069 was raised from the vendor&apos;s 9.4 to 9.5 Critical, and the published vector reads AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, scoring the backend login as an attack requirement (AT:P) rather than a privilege (PR:L).</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>J2Store / J2Commerce</category><category>Critical</category></item><item><title>CVE-2026-78000 - J2Store / J2Commerce (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78000/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78000/</guid><description>J2Store 3.3.21 on the Joomla 3 branch is affected by five vulnerabilities in com_j2store, disclosed by Phil Taylor (mySites.guru) and fixed by J2Commerce on 31 August 2026. CVE-2026-78069 (CVSS 9.5, Critical): the administrator Apps controller instantiates app-plugin controllers through an appTask delegation path with no com_j2store ACL check anywhere in the code, and the backend node of fof.xml declares no view ACL at all, so FOF defaults an unmatched task to allow rather than deny. Any authenticated Joomla backend user, holding no J2Store permission whatsoever, can trigger #__j2store_* table truncation and traversal-based SQL file execution; only the Joomla core administrator login wall keeps anonymous visitors out, and that checks nothing about com_j2store permissions. CVE-2026-78064 (CVSS 8.8, High): the carts view inherits the generic FOF save task under a wildcard true ACL in fof.xml, and FOF enforces CSRF tokens only on backend HTML requests, not on frontend format=raw requests, so an unauthenticated POST can insert cart rows with an attacker-chosen user_id or session_id, or overwrite an existing row by id. CVE-2026-77999 (CVSS 8.7, High): the PayPal IPN listener treated UNVERIFIED and any non-INVALID response as valid, made its verification request with CURLOPT_SSL_VERIFYPEER disabled, and stored the verdict in a field nothing downstream read, so processing continued regardless of the outcome; separately, omitting mc_gross from the POST body skipped the paid-amount comparison entirely. Unauthenticated requests could confirm orders that were never paid for, or fail legitimate ones. CVE-2026-78065 (CVSS 7.1, High): editAddress() redirected non-owners away only when the loaded address row had a non-empty user_id, and guest checkout rows have none, so any logged-in account guessing a small sequential address_id was shown a guest customer full name, street address and phone number prefilled into the edit form. CVE-2026-78000 (CVSS 5.3, Medium): filter_tag, pricefrom and priceto are echoed unescaped into a hidden input value attribute by J2Html::input(), across all six shipped product-tags templates, giving reflected XSS from a crafted link with no click beyond the initial navigation. FIX: update to 3.3.22 on this Joomla 3 branch (the equivalent fixes are 4.0.22 on 4.0.x and 4.1.7 on 4.1.x). If you cannot update immediately: disable PayPal, or watch pending orders for CONFIRMED or FAILED transitions with no matching PayPal transaction; disable guest checkout; and review every Joomla backend account regardless of privilege level, because the Apps controller issue needs a backend login but no J2Store permission. All five CVE records were published by the Joomla CNA on 3 September 2026 and all five credit Phil Taylor, mySites.guru. The affected ranges are unchanged. Four scores match the vendor advisory; CVE-2026-78069 was raised from the vendor&apos;s 9.4 to 9.5 Critical, and the published vector reads AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, scoring the backend login as an attack requirement (AT:P) rather than a privilege (PR:L).</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>J2Store / J2Commerce</category><category>Critical</category></item><item><title>CVE-2026-77999 - J2Store / J2Commerce (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-77999/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-77999/</guid><description>J2Store 3.3.21 on the Joomla 3 branch is affected by five vulnerabilities in com_j2store, disclosed by Phil Taylor (mySites.guru) and fixed by J2Commerce on 31 August 2026. CVE-2026-78069 (CVSS 9.5, Critical): the administrator Apps controller instantiates app-plugin controllers through an appTask delegation path with no com_j2store ACL check anywhere in the code, and the backend node of fof.xml declares no view ACL at all, so FOF defaults an unmatched task to allow rather than deny. Any authenticated Joomla backend user, holding no J2Store permission whatsoever, can trigger #__j2store_* table truncation and traversal-based SQL file execution; only the Joomla core administrator login wall keeps anonymous visitors out, and that checks nothing about com_j2store permissions. CVE-2026-78064 (CVSS 8.8, High): the carts view inherits the generic FOF save task under a wildcard true ACL in fof.xml, and FOF enforces CSRF tokens only on backend HTML requests, not on frontend format=raw requests, so an unauthenticated POST can insert cart rows with an attacker-chosen user_id or session_id, or overwrite an existing row by id. CVE-2026-77999 (CVSS 8.7, High): the PayPal IPN listener treated UNVERIFIED and any non-INVALID response as valid, made its verification request with CURLOPT_SSL_VERIFYPEER disabled, and stored the verdict in a field nothing downstream read, so processing continued regardless of the outcome; separately, omitting mc_gross from the POST body skipped the paid-amount comparison entirely. Unauthenticated requests could confirm orders that were never paid for, or fail legitimate ones. CVE-2026-78065 (CVSS 7.1, High): editAddress() redirected non-owners away only when the loaded address row had a non-empty user_id, and guest checkout rows have none, so any logged-in account guessing a small sequential address_id was shown a guest customer full name, street address and phone number prefilled into the edit form. CVE-2026-78000 (CVSS 5.3, Medium): filter_tag, pricefrom and priceto are echoed unescaped into a hidden input value attribute by J2Html::input(), across all six shipped product-tags templates, giving reflected XSS from a crafted link with no click beyond the initial navigation. FIX: update to 3.3.22 on this Joomla 3 branch (the equivalent fixes are 4.0.22 on 4.0.x and 4.1.7 on 4.1.x). If you cannot update immediately: disable PayPal, or watch pending orders for CONFIRMED or FAILED transitions with no matching PayPal transaction; disable guest checkout; and review every Joomla backend account regardless of privilege level, because the Apps controller issue needs a backend login but no J2Store permission. All five CVE records were published by the Joomla CNA on 3 September 2026 and all five credit Phil Taylor, mySites.guru. The affected ranges are unchanged. Four scores match the vendor advisory; CVE-2026-78069 was raised from the vendor&apos;s 9.4 to 9.5 Critical, and the published vector reads AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, scoring the backend login as an attack requirement (AT:P) rather than a privilege (PR:L).</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><category>J2Store / J2Commerce</category><category>Critical</category></item><item><title>CVE-2026-78374 - T4 Page Builder (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78374/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78374/</guid><description>JoomlArt released T4 Page Builder 2.3.0 on 28 August 2026, fixing an unauthenticated open mail relay that mySites.guru reported to the vendor and to the Joomla Security Strike Team on 17 August 2026, after finding it in use on a client site. In versions below 2.3.0 the front-end contact action is exempt from the component&apos;s ACL checks and accepts a recipient address supplied in the request, so any anonymous visitor can send mail to arbitrary addresses using the site&apos;s configured sender identity: the site becomes an open mail relay for spam and phishing sent under its own domain, SPF and DKIM. The same endpoint requires no Joomla form token (CSRF), applies no rate limiting, and relies on whether a captcha plugin is enabled rather than validating a captcha response. The subscribe task on the same endpoint allows unauthenticated writes to connected AcyMailing subscription tables. The component also ships a live Mailchimp API key hardcoded into its source, which should be rotated by its owner. mySites.guru verified the fix by auditing the released 2.3.0 package on 3 September 2026: the contact action now requires a valid form token, rate limits per IP (5 requests per 10 minutes by default), validates captcha explicitly, and delivers only to administrator addresses via getAdminMails() rather than the request-supplied recipient. The hardcoded key is absent from the 2.3.0 package and the Mailchimp credentials are read from component parameters. Update to T4 Page Builder 2.3.0 or later from the JoomlArt member area, clear the Joomla cache, then re-test all contact and subscription forms. Temporary mitigation: unpublish public contact and subscription forms built with T4 Page Builder until the update is applied. CVE-2026-78374 was assigned by the Joomla CNA on 10 September 2026, at the reporter&apos;s request rather than the vendor&apos;s. The record is reserved and not yet published at MITRE or NVD, and JoomlArt still credits no reporter. The vendor states no affected floor, so every version below 2.3.0 is treated as affected.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><category>T4 Page Builder</category><category>High</category></item><item><title>CVE-2026-78073 - All Video Share (Medium)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78073/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78073/</guid><description>All Video Share fails to escape a number of user supplied inputs, giving reflected cross-site scripting vectors that need no authentication (CVSS 4.0 vector PR:N, UI:P - the victim must follow a crafted link). Reported by Krzysztof Zajac of CERT PL. NOTE ON THE AFFECTED RANGE: the CVE record contradicts itself. Its structured affected-version field states 1.0.0 to 4.4.99, meaning the flaw is fixed in 4.5.0, while its own title and description both state the range as 1.0.0 to 4.5.0, which would make 4.5.0 affected as well. This rule follows the structured field, so 4.5.0 is treated as fixed. The record also names the vendor inconsistently, as j2commerce.com in the title and mrvinoth.com in the affected block; every installation seen on the platform is Vinoth Kumar / MrVinoth. The CVE gives one continuous affected range from 1.0.0 and no backport to the older 2.x or 3.x lines has been published, so sites still on those lines have no fixed release on their own branch and must move to 4.5.0 or later.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><category>All Video Share</category><category>Medium</category></item><item><title>CVE-2026-78072 - Sexy Polling Reloaded (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78072/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78072/</guid><description>Sexy Polling Reloaded contains a blind SQL injection that needs no login, no token and no user interaction (CVSS 4.0 vector PR:N, base score 8.7 High), allowing an anonymous visitor to read arbitrary data from the site database. Reported by Krzysztof Zajac of CERT PL. The vendor, Jefferson49, maintains two parallel release lines and shipped the fix to both on 2026-07-25: 5.0.6.1 for the Joomla 3.10 and 4 line, and 5.6.1 for the Joomla 4, 5 and 6 line. Because 5.0.6.1 sorts below 5.6.1, a single rule written to the CVE ceiling of 5.6.1 would wrongly flag the patched legacy build, so this advisory is split into one rule per branch.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><category>Sexy Polling Reloaded</category><category>High</category></item><item><title>CVE-2026-78071 - DPCalendar (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78071/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78071/</guid><description>DPCalendar renders a calendar location title into a data-title HTML attribute without escaping it, giving a stored cross-site scripting flaw. A payload such as x&quot; onmouseover=&quot;alert(1) has no HTML tags, so it passes through the filterText input filter unchanged and breaks out of the attribute on output, where it becomes a live event handler. Storing the payload requires an account with DPCalendar location create permission (CVSS 4.0 vector PR:H), but the script then runs in the browser of every visitor who views that location page, so the permission bounds who can plant it and not who it hits. This was reported in two stages. Toan Le found the original as vendor issue 12203, fixed on 2026-08-27 in 8.19.5 and 10.12.0, which escaped nine of the ten data-title sinks in the component. mySites.guru proved the same day that the tenth was still open, at components/com_dpcalendar/site/tmpl/location/default_map.php line 23, reported it to Digital Peak and the Joomla Security Strike Team, and Digital Peak confirmed it on 2026-08-28. That last sink was closed on 2026-09-10 in 8.19.6 and 10.12.1, along with seven identical sinks in the free mod_dpcalendar_upcoming module templates (blog, default, horizontal, icon, panel, simple and timeline). CVE-2026-78071 was updated on 2026-09-10 to widen its affected range to 7.0.0-8.19.5 and 9.0.0-10.12.0 and to credit both finders. On Joomla 3 the fixed version is 8.19.6, which is a security-only release containing this one change. If you have overridden the DPCalendar location templates, the unescaped output is still in your override and updating the extension will not reach it.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><category>DPCalendar</category><category>High</category></item><item><title>CVE-2026-78070 - DPCalendar (Medium)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-78070/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-78070/</guid><description>DPCalendar contains a blind SQL injection reachable by saving a Joomla article. The DPCalendar content plugin passes the order and orderdir parameters of a {dpcalendar} tag into the events query ORDER BY clause without validating them against the model filter_fields allow-list. The sink used the database escape() helper, which secures string literals but not SQL identifiers, so the sort column is injectable. Exploitation requires an account holding permission to create or update articles, so this is authenticated and privileged (CVSS 4.0 vector PR:H), not anonymous. Reported by Toan Le as vendor issue 12206. Fixed in 10.12.0 on the Joomla 4 to 6 branch and backported to 8.19.5 on the Joomla 3 branch. Temporary mitigation: disable the &quot;Content - DPCalendar&quot; plugin, which is the only route in.</description><pubDate>Fri, 28 Aug 2026 00:00:00 GMT</pubDate><category>DPCalendar</category><category>Medium</category></item><item><title>CVE-2026-77991 - JEM - Joomla Event Manager (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-77991/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-77991/</guid><description>JEM (Joomla Event Manager) by the JEM Community is affected by multiple vulnerabilities confirmed live against JEM 5. The Joomla Security Strike Team assigned five CVE IDs on 22 August 2026 and published all five records on 27 August 2026: CVE-2026-77991, CVE-2026-77034, CVE-2026-77035, CVE-2026-77989 and CVE-2026-77990. Every record gives the affected range as 1.0.0 to 5.0.0. There is still no stable version to update to. The fixes exist only in a public 5.0.1 release candidate (the 5.0.1-bugfixes branch on GitHub). The newest stable release remains 5.0.0-stable, from 8 July 2026, which is affected. Confirmed issues: (1) Privileged remote code execution (CVE-2026-77991, CVSS 9.4 Critical) - the administrator source model writes dangerous file types including PHP, giving code execution to an account that already holds administrator access. (2) Unauthenticated article overwrite and force-publish (CVE-2026-77034, CVSS 6.9) - the front-end event.updateAssociatedArticle task performs no ACL check before writing a Joomla content article, so any visitor holding their own session token can republish and overwrite an article associated with an event, including publishing an unpublished one. (3) Cross-user event and venue takeover (CVE-2026-77035, CVSS 5.1) - allowEdit() trusts jform[created_by] and jform[access] from POST data, so a registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user&apos;s record id together with their own id as created_by and take over that record. (4) Reflected XSS via the PDF export link (CVE-2026-77989, CVSS 5.3) - buildCurrentPdfLink copies the current request query string into the PDF button URL and pdfbutton() echoes it unescaped (attribute injection, no tags required). (5) Attendee data disclosure (CVE-2026-77990, CVSS 5.3) - any logged-in non-manager can read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events. One further item found by code reading, stored XSS through unescaped category names, has no CVE. Mitigation until 5.0.1 stable ships: restrict front-end event and venue editing and the front-end attendees view to trusted users only, consider disabling front-end event submission, and review who holds administrator access on the site given the source-model file write. Update to JEM 5.0.1 or later as soon as a stable release is available. This rule flags every JEM version below 5.0.1, which matches the affected range stated in all five CVE records.</description><pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate><category>JEM - Joomla Event Manager</category><category>Critical</category></item><item><title>CVE-2026-77990 - JEM - Joomla Event Manager (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-77990/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-77990/</guid><description>JEM (Joomla Event Manager) by the JEM Community is affected by multiple vulnerabilities confirmed live against JEM 5. The Joomla Security Strike Team assigned five CVE IDs on 22 August 2026 and published all five records on 27 August 2026: CVE-2026-77991, CVE-2026-77034, CVE-2026-77035, CVE-2026-77989 and CVE-2026-77990. Every record gives the affected range as 1.0.0 to 5.0.0. There is still no stable version to update to. The fixes exist only in a public 5.0.1 release candidate (the 5.0.1-bugfixes branch on GitHub). The newest stable release remains 5.0.0-stable, from 8 July 2026, which is affected. Confirmed issues: (1) Privileged remote code execution (CVE-2026-77991, CVSS 9.4 Critical) - the administrator source model writes dangerous file types including PHP, giving code execution to an account that already holds administrator access. (2) Unauthenticated article overwrite and force-publish (CVE-2026-77034, CVSS 6.9) - the front-end event.updateAssociatedArticle task performs no ACL check before writing a Joomla content article, so any visitor holding their own session token can republish and overwrite an article associated with an event, including publishing an unpublished one. (3) Cross-user event and venue takeover (CVE-2026-77035, CVSS 5.1) - allowEdit() trusts jform[created_by] and jform[access] from POST data, so a registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user&apos;s record id together with their own id as created_by and take over that record. (4) Reflected XSS via the PDF export link (CVE-2026-77989, CVSS 5.3) - buildCurrentPdfLink copies the current request query string into the PDF button URL and pdfbutton() echoes it unescaped (attribute injection, no tags required). (5) Attendee data disclosure (CVE-2026-77990, CVSS 5.3) - any logged-in non-manager can read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events. One further item found by code reading, stored XSS through unescaped category names, has no CVE. Mitigation until 5.0.1 stable ships: restrict front-end event and venue editing and the front-end attendees view to trusted users only, consider disabling front-end event submission, and review who holds administrator access on the site given the source-model file write. Update to JEM 5.0.1 or later as soon as a stable release is available. This rule flags every JEM version below 5.0.1, which matches the affected range stated in all five CVE records.</description><pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate><category>JEM - Joomla Event Manager</category><category>Critical</category></item><item><title>CVE-2026-77989 - JEM - Joomla Event Manager (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-77989/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-77989/</guid><description>JEM (Joomla Event Manager) by the JEM Community is affected by multiple vulnerabilities confirmed live against JEM 5. The Joomla Security Strike Team assigned five CVE IDs on 22 August 2026 and published all five records on 27 August 2026: CVE-2026-77991, CVE-2026-77034, CVE-2026-77035, CVE-2026-77989 and CVE-2026-77990. Every record gives the affected range as 1.0.0 to 5.0.0. There is still no stable version to update to. The fixes exist only in a public 5.0.1 release candidate (the 5.0.1-bugfixes branch on GitHub). The newest stable release remains 5.0.0-stable, from 8 July 2026, which is affected. Confirmed issues: (1) Privileged remote code execution (CVE-2026-77991, CVSS 9.4 Critical) - the administrator source model writes dangerous file types including PHP, giving code execution to an account that already holds administrator access. (2) Unauthenticated article overwrite and force-publish (CVE-2026-77034, CVSS 6.9) - the front-end event.updateAssociatedArticle task performs no ACL check before writing a Joomla content article, so any visitor holding their own session token can republish and overwrite an article associated with an event, including publishing an unpublished one. (3) Cross-user event and venue takeover (CVE-2026-77035, CVSS 5.1) - allowEdit() trusts jform[created_by] and jform[access] from POST data, so a registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user&apos;s record id together with their own id as created_by and take over that record. (4) Reflected XSS via the PDF export link (CVE-2026-77989, CVSS 5.3) - buildCurrentPdfLink copies the current request query string into the PDF button URL and pdfbutton() echoes it unescaped (attribute injection, no tags required). (5) Attendee data disclosure (CVE-2026-77990, CVSS 5.3) - any logged-in non-manager can read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events. One further item found by code reading, stored XSS through unescaped category names, has no CVE. Mitigation until 5.0.1 stable ships: restrict front-end event and venue editing and the front-end attendees view to trusted users only, consider disabling front-end event submission, and review who holds administrator access on the site given the source-model file write. Update to JEM 5.0.1 or later as soon as a stable release is available. This rule flags every JEM version below 5.0.1, which matches the affected range stated in all five CVE records.</description><pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate><category>JEM - Joomla Event Manager</category><category>Critical</category></item><item><title>CVE-2026-77035 - JEM - Joomla Event Manager (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-77035/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-77035/</guid><description>JEM (Joomla Event Manager) by the JEM Community is affected by multiple vulnerabilities confirmed live against JEM 5. The Joomla Security Strike Team assigned five CVE IDs on 22 August 2026 and published all five records on 27 August 2026: CVE-2026-77991, CVE-2026-77034, CVE-2026-77035, CVE-2026-77989 and CVE-2026-77990. Every record gives the affected range as 1.0.0 to 5.0.0. There is still no stable version to update to. The fixes exist only in a public 5.0.1 release candidate (the 5.0.1-bugfixes branch on GitHub). The newest stable release remains 5.0.0-stable, from 8 July 2026, which is affected. Confirmed issues: (1) Privileged remote code execution (CVE-2026-77991, CVSS 9.4 Critical) - the administrator source model writes dangerous file types including PHP, giving code execution to an account that already holds administrator access. (2) Unauthenticated article overwrite and force-publish (CVE-2026-77034, CVSS 6.9) - the front-end event.updateAssociatedArticle task performs no ACL check before writing a Joomla content article, so any visitor holding their own session token can republish and overwrite an article associated with an event, including publishing an unpublished one. (3) Cross-user event and venue takeover (CVE-2026-77035, CVSS 5.1) - allowEdit() trusts jform[created_by] and jform[access] from POST data, so a registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user&apos;s record id together with their own id as created_by and take over that record. (4) Reflected XSS via the PDF export link (CVE-2026-77989, CVSS 5.3) - buildCurrentPdfLink copies the current request query string into the PDF button URL and pdfbutton() echoes it unescaped (attribute injection, no tags required). (5) Attendee data disclosure (CVE-2026-77990, CVSS 5.3) - any logged-in non-manager can read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events. One further item found by code reading, stored XSS through unescaped category names, has no CVE. Mitigation until 5.0.1 stable ships: restrict front-end event and venue editing and the front-end attendees view to trusted users only, consider disabling front-end event submission, and review who holds administrator access on the site given the source-model file write. Update to JEM 5.0.1 or later as soon as a stable release is available. This rule flags every JEM version below 5.0.1, which matches the affected range stated in all five CVE records.</description><pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate><category>JEM - Joomla Event Manager</category><category>Critical</category></item><item><title>CVE-2026-77034 - JEM - Joomla Event Manager (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-77034/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-77034/</guid><description>JEM (Joomla Event Manager) by the JEM Community is affected by multiple vulnerabilities confirmed live against JEM 5. The Joomla Security Strike Team assigned five CVE IDs on 22 August 2026 and published all five records on 27 August 2026: CVE-2026-77991, CVE-2026-77034, CVE-2026-77035, CVE-2026-77989 and CVE-2026-77990. Every record gives the affected range as 1.0.0 to 5.0.0. There is still no stable version to update to. The fixes exist only in a public 5.0.1 release candidate (the 5.0.1-bugfixes branch on GitHub). The newest stable release remains 5.0.0-stable, from 8 July 2026, which is affected. Confirmed issues: (1) Privileged remote code execution (CVE-2026-77991, CVSS 9.4 Critical) - the administrator source model writes dangerous file types including PHP, giving code execution to an account that already holds administrator access. (2) Unauthenticated article overwrite and force-publish (CVE-2026-77034, CVSS 6.9) - the front-end event.updateAssociatedArticle task performs no ACL check before writing a Joomla content article, so any visitor holding their own session token can republish and overwrite an article associated with an event, including publishing an unpublished one. (3) Cross-user event and venue takeover (CVE-2026-77035, CVSS 5.1) - allowEdit() trusts jform[created_by] and jform[access] from POST data, so a registered user with edit-own rights (the eventowner=1 setting or core.edit.own) can POST another user&apos;s record id together with their own id as created_by and take over that record. (4) Reflected XSS via the PDF export link (CVE-2026-77989, CVSS 5.3) - buildCurrentPdfLink copies the current request query string into the PDF button URL and pdfbutton() echoes it unescaped (attribute injection, no tags required). (5) Attendee data disclosure (CVE-2026-77990, CVSS 5.3) - any logged-in non-manager can read attendee names, usernames, registration dates and statuses for events they do not manage, including lists belonging to unpublished events. One further item found by code reading, stored XSS through unescaped category names, has no CVE. Mitigation until 5.0.1 stable ships: restrict front-end event and venue editing and the front-end attendees view to trusted users only, consider disabling front-end event submission, and review who holds administrator access on the site given the source-model file write. Update to JEM 5.0.1 or later as soon as a stable release is available. This rule flags every JEM version below 5.0.1, which matches the affected range stated in all five CVE records.</description><pubDate>Thu, 27 Aug 2026 00:00:00 GMT</pubDate><category>JEM - Joomla Event Manager</category><category>Critical</category></item><item><title>CVE-2026-77998 - miniOrange SAML SSO (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-77998/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-77998/</guid><description>miniOrange SAML SSO for Joomla is affected by an unauthenticated authentication bypass, CVE-2026-77998, scored CVSS 4.0 10.0 (critical). UtilitiesSAML::validateSignature() performs a loose boolean check on the tri-state integer returned by PHP openssl_verify(), so the error return value of -1 is treated as truthy and therefore as a successful signature verification. An unauthenticated attacker can submit a crafted SAMLResponse holding an attacker-controlled NameID together with a deliberately malformed signature value that triggers an OpenSSL processing error, bypassing verification entirely and logging in as any existing user, administrators included. FIXED VERSIONS: miniOrange ships this extension as several separately numbered editions, and the leading digit identifies the EDITION rather than the age, so a higher version number is not necessarily newer. Free edition is fixed in 11.0.2 (and 6.4 for the ADFS and Google Apps editions). The paid SAML SP editions were announced to miniOrange customers on 26 August 2026 and confirmed publicly the same day by David Jardin of the Joomla Security Strike Team: Basic is affected up to 13.1 and fixed in 13.2; Standard is affected up to 24.1 and fixed in 24.2; Premium is affected up to 34.1 and fixed in 34.2; Enterprise is affected up to 44.1 and fixed in 44.2. UPDATE PATH WARNING: miniOrange state that 13.0, 13.1, 24.0, 24.1, 34.0, 34.1, 44.0 and 44.1 can install the fixed release directly over the top, but anything below 13.0, 24.0, 34.0 or 44.0 must be uninstalled first and then reinstalled. On a site where SAML is the only login method, uninstalling the plugin locks every user out, administrators included, so confirm you have a working local Joomla Super User account and a current backup before you start. If the plugin was customised for you, save its configuration and tell miniOrange before replacing it. NOTE ON THE CVE RECORD: as at 26 August 2026 the published CVE record still gives its affected range as 1.0.0 to 11.0.1, which describes the free edition only, and it has not been re-scoped to cover the paid editions. This rule set deliberately goes beyond the range stated in the CVE, on the strength of the vendor written statement of the paid fix versions. If you cannot update immediately, disable or remove the extension rather than leaving an anonymous administrator login available.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>miniOrange SAML SSO</category><category>Critical</category></item><item><title>CVE-2026-77997 - YOOtheme Pro (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-77997/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-77997/</guid><description>YOOtheme Pro 5.0.41&apos;s Page Builder module controller (ModuleController::getModule()) had no permission check of its own, unlike its sibling save endpoint which already required core.edit on com_modules.module.{id}. Reaching it via GET /index.php?option=com_ajax&amp;p=/module&amp;id=&lt;id&gt; returned that module&apos;s title, full params JSON (which can include API keys, raw HTML or JS, and other sensitive module configuration) and rendered content, for any module id on the site, published or unpublished. Published as CVE-2026-77997 by the Joomla CNA on 25 August 2026, CVSS 4.0 base 5.1 Medium (AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N). The affected range on the record is 1.0.0 to 5.0.41. Exploitation requires an authenticated user who already holds core.edit on com_templates. YOOtheme&apos;s CheckUserPermission middleware runs on every route the framework dispatches and aborts with 403 (or redirects a guest to the login page) unless that permission is held, and the /module route does not opt out of it as the newsletter and image routes do. This is therefore a privilege boundary crossed sideways rather than an anonymous read: a user trusted to edit templates could read the configuration of any module on the site without holding any com_modules permission at all. Fixed in 5.0.42, which adds an explicit $user-&gt;authorise(&apos;core.edit&apos;, &apos;com_modules.module.{id}&apos;) check to getModule(). Confirmed by diffing the 5.0.41 and 5.0.42 packages and tracing the full request path. Note that YOOtheme Pro installs as both a template and a system plugin, and both report the element yootheme, so a single site normally shows two rows for this. Updating YOOtheme Pro updates both together. Update YOOtheme Pro to 5.0.42 or later through the Joomla Extensions manager, or download it from your YOOtheme account.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>YOOtheme Pro</category><category>High</category></item><item><title>CVE-2026-77996 - YOOtheme Pro (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-77996/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-77996/</guid><description>YOOtheme Pro 5.0.41&apos;s Location custom field (plg_fields_location) rendered its stored value straight into a hidden input&apos;s HTML attribute with no escaping, because LocationField::getInput() built that markup by plain string interpolation. A stored attribute-breakout payload therefore fires when the item&apos;s edit form is next opened by anyone, up to and including a Super User. Published as CVE-2026-77996 by the Joomla CNA on 25 August 2026, CVSS 4.0 base 7.5 High (AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:N/SI:N/SA:N). The affected range on the record is 1.0.0 to 5.0.41. The CNA classes this as authenticated and privileged: storing the payload needs rights to edit an item that carries the field, and it only fires when someone later opens that item&apos;s edit form. As a Joomla custom field it can attach to articles, contacts, categories or users, so the practical exposure on any given site depends on which of those the field is attached to and who can edit them. Fixed in 5.0.42, which wraps the value in htmlspecialchars(..., ENT_QUOTES, &apos;UTF-8&apos;). Confirmed by diffing the 5.0.41 and 5.0.42 packages. Note: this extension&apos;s technical identity (type=plugin, folder=fields, element=location) collides with two unrelated third-party extensions also named &quot;Fields - Location&quot;, from developers Michael Richey and DigitAll Tools. Re-checked against live install data on 25 August 2026: they top out at 5.0.5 and 1.0 respectively, both below this rule&apos;s 5.0.41 floor, so neither is caught. Any future widening of this rule&apos;s floor must re-check that install base first. Update YOOtheme Pro to 5.0.42 or later through the Joomla Extensions manager, or download it from your YOOtheme account.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>YOOtheme Pro</category><category>High</category></item><item><title>CVE-2026-76613 - YOOtheme Pro (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-76613/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-76613/</guid><description>YOOtheme Pro below 4.5.34, the Joomla 3 branch, has three flaws reachable by an authenticated user who can edit templates. CVE-2026-76613 (CVSS 8.6) is an SQL injection in the page builder&apos;s article and tag source ORDER BY handling. CVE-2026-75115 (CVSS 7.0) is an arbitrary file read via a glob-pattern escape in the Filesystem source path filter. CVE-2026-77997 (CVSS 5.1) is a missing authorisation check in the module controller that returns any module&apos;s configuration to a user who holds only com_templates edit rights. All three are fixed in 4.5.34, released 24 August 2026. Update to 4.5.35, released 25 August 2026, which adds a regression fix for custom-field ordering in the Articles model. Sites on 1.x, 2.x, 3.x or 4.0 to 4.4 have no fixed release on their own line: the fix is to move to 4.5.35, or to migrate to the 5.0.x branch on Joomla 4/5/6. All three CVEs are scored PR:H, so an attacker needs an existing privileged account rather than anonymous access.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>YOOtheme Pro</category><category>High</category></item><item><title>CVE-2026-75115 - YOOtheme Pro (High)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-75115/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-75115/</guid><description>YOOtheme Pro below 4.5.34, the Joomla 3 branch, has three flaws reachable by an authenticated user who can edit templates. CVE-2026-76613 (CVSS 8.6) is an SQL injection in the page builder&apos;s article and tag source ORDER BY handling. CVE-2026-75115 (CVSS 7.0) is an arbitrary file read via a glob-pattern escape in the Filesystem source path filter. CVE-2026-77997 (CVSS 5.1) is a missing authorisation check in the module controller that returns any module&apos;s configuration to a user who holds only com_templates edit rights. All three are fixed in 4.5.34, released 24 August 2026. Update to 4.5.35, released 25 August 2026, which adds a regression fix for custom-field ordering in the Articles model. Sites on 1.x, 2.x, 3.x or 4.0 to 4.4 have no fixed release on their own line: the fix is to move to 4.5.35, or to migrate to the 5.0.x branch on Joomla 4/5/6. All three CVEs are scored PR:H, so an attacker needs an existing privileged account rather than anonymous access.</description><pubDate>Tue, 25 Aug 2026 00:00:00 GMT</pubDate><category>YOOtheme Pro</category><category>High</category></item><item><title>CVE-2026-77995 - miniOrange OAuth Client (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-77995/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-77995/</guid><description>miniOrange OAuth Client versions 1.0.0 to 3.1.9 are affected by an unauthenticated account takeover, CVE-2026-77995, scored CVSS 4.0 10.0 (critical). Manipulation of a cookie value allows an attacker with no login to authenticate as an arbitrary account, Super Users included. Update the miniOrange OAuth Client to 3.2.0 or later. IMPORTANT edition caveat: miniOrange ships several separately numbered OIDC editions under this same com_miniorange_oauth element, including Login with Azure AD, Login with Keycloak OAuth Single Sign-On and Single Sign-On for Educational Institutes. miniOrange confirmed in writing on 26 August 2026 that those three are fixed in 1.2.2, not 3.2.0, and that all of the fixed versions they gave apply to the free editions only. Check the display name of the installed extension before acting on a version number, and if the site reports a two-segment version such as 32.0.1 or 34.0.0 it is a paid edition. miniOrange stated in writing on 4 September 2026 that CVE-2026-77995 was associated only with the free OAuth Client and that their investigation found the flaw in no version of the paid OAuth editions, which is why no paid security build was ever released. This rule&apos;s ceiling of 3.1.9 therefore excludes every paid build on purpose, and no paid install has ever been flagged by it. Note that this rests on the vendor&apos;s assessment: the CVE record still names a single product with no edition qualifier, and the same vendor scoped the SAML record to the free line before it had to be widened to name all four paid editions.</description><pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate><category>miniOrange OAuth Client</category><category>Critical</category></item><item><title>CVE-2026-77992 - Fabrik (Critical)</title><link>https://mysites.guru/vulnerabilities/CVE-2026-77992/</link><guid isPermaLink="true">https://mysites.guru/vulnerabilities/CVE-2026-77992/</guid><description>Fabrik (the Joomla form and list builder by Fabrikar) shipped a series of security releases across the 4.7.x line. 4.7.2 is the release mySites.guru has verified, and 4.7.0 and 4.7.1 are missing part of that work. The calc element in this component carried a published unauthenticated remote code execution vulnerability (CVE-2026-66915 and CVE-2026-67282, both CVSS 10.0). mySites.guru worked with Fabrikar through the 4.7.x releases under coordinated disclosure, and 4.7.2 closes the issues raised. What to do: update Fabrik to 4.7.2, downloaded from fabrikar.com. Until you have, restrict front-end access to Fabrik forms and lists to trusted users. Sites below 4.7.0 are covered by a separate rule and remain exposed to the published CVSS 10.0 RCE.</description><pubDate>Sat, 22 Aug 2026 00:00:00 GMT</pubDate><category>Fabrik</category><category>Critical</category></item></channel></rss>