Gridbox (com_gridbox) below 2.20.2 - Multiple Unauthenticated RCE, SQL Injection and Authentication Bypass (CVE-2026-65884, CVE-2026-65885 and others, actively exploited, fixed in 2.20.2)
A full security audit of Gridbox (component com_gridbox) found 23 vulnerabilities, including an unauthenticated arbitrary file upload that yields remote code execution in a single request, multiple unauthenticated SQL injection points (one returns every user password hash), several routes to administrator access with no password, and a registration flaw that lets any visitor create an administrator account. Several are being actively exploited in the wild, confirmed by the Joomla Security Strike Team and observed by us in server logs and on compromised sites. The Joomla CNA has assigned CVE IDs grouped by shared root cause rather than one per finding. Published so far: CVE-2026-65884 (registration accepts user-supplied group IDs, so an anonymous visitor can register with administrator permissions; CWE-284; CVSS 4.0 10.0 Critical; exploit maturity Attacked) and CVE-2026-65885 (authenticated arbitrary file upload, which becomes remote code execution when chained with CVE-2026-65884 because the attacker can create the account it needs; CWE-434; CVSS 4.0 9.4 Critical; exploit maturity Attacked). Nine further IDs are reserved and not yet public: CVE-2026-65886, CVE-2026-65887, CVE-2026-65888, CVE-2026-65889, CVE-2026-65890, CVE-2026-65947, CVE-2026-66488, CVE-2026-66489 and CVE-2026-66490. A separate earlier authentication bypass, CVE-2026-61425, was fixed in 2.20.1. Fixed in the Gridbox 2.20.2 security release (29 July 2026): update every Gridbox site now. Every version before it, 1.0.0 to 2.20.1, is affected. Any site that has run an affected version may already be compromised: check for unexpected administrator accounts (in any group, not just Super Users), new or modified files, and PHP files in upload folders, and rotate administrator credentials. fix.mysites.guru can clean a compromised site (GBP 120, a single fixed fee, usually same day).
Affected versions: < 2.20.2
Full advisory: our disclosure post

