Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

JCH Optimize security vulnerabilities

mySites.guru tracks 1 vulnerability in JCH Optimize (com_jchoptimize). Every connected Joomla site is checked against it on each audit.

Is my site affected?

Your site is affected if it runs JCH Optimize in this range:

  • before 9.4.0
Latest safe version
9.4.0 or later. No rule we check matches that release or any newer one.
What to do
Update JCH Optimize to 9.4.0 or later from the vendor, then confirm the installed version on the Joomla administrator's Extensions: Manage screen.

Every JCH Optimize vulnerability we track

Newest first. CVSS is the score published in each CVE record, where it has one; the severity column is the rating our check uses.

CVEAffected versionsFixed inSeverityAdded
No CVE idbefore 9.4.09.4.0High2026-10-07

What we check for

High2026-10-07

JCH Optimize (com_jchoptimize) below 9.4.0 - Unauthenticated XSS and Page Cache Hit Counter Access Control Bypass, plus Admin CSRF and Open Redirect

JCH Optimize versions before 9.4.0 contain several flaws the vendor rates HIGH. A cross-site scripting issue let encoded characters in URLs, such as search query links, be decoded during optimization. The Page Cache hit counter exposed an unauthenticated com_ajax endpoint that took the component and model names from the request and called that model's hit() method, so any visitor could drive hit counters on content the page cache never served and read back exception messages. A jchbackend URL parameter let any visitor switch optimization off. Administrator tasks that change settings or files did not require a valid form token and administrator permissions (CSRF), the Mode Switcher and Utility tasks redirected to any URL passed in the return parameter, and image URLs and paths returned by the image optimization service were not validated or kept inside the site root. MEDIUM-rated fixes cover unescaped file and folder names in the Optimize Images tree and malformed Host headers influencing Page Cache and Capture Cache keys and file paths. Settings exports no longer include the Cloudflare API token or Redis password. No CVE has been assigned at the time of writing. Update to JCH Optimize 9.4.0 or later (the release notes require PHP 8.1 and Joomla 5.0, although the update feed still offers it to Joomla 4.4). There is no patched release for older branches.

Affected versions: < 9.4.0

Full advisory: our disclosure post

Timeline

  1. 7 October 2026Check added for a flaw with no CVE id (before 9.4.0)

References

JCH Optimize vulnerability questions

Which versions of JCH Optimize are vulnerable?
mySites.guru tracks one vulnerability in JCH Optimize (com_jchoptimize). A site is affected if its installed version is in this range: before 9.4.0.
What is the latest safe version of JCH Optimize?
9.4.0. Every vulnerability tracked here is fixed by 9.4.0, and no rule we check matches that release or any later one.
How do I check which version of JCH Optimize my Joomla site runs?
The installed version is listed on the Joomla administrator's Extensions: Manage screen; search it for com_jchoptimize. mySites.guru reads the installed version on every audit of a connected site and checks it against this rule.

Running JCH Optimize on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

Rules current as of 7 October 2026.