High
Visforms (com_visforms) 6.0.0 to below 6.2.1 - Authenticated Arbitrary File Write (RCE), Arbitrary File Delete, Permission Bypasses and Unauthenticated Mail Amplification
Visforms ships a set of flaws credited by vi-solutions to the security researcher Yukusawa18. The most serious is an arbitrary file write: the CSS editor in the administrator Vistools model takes its target file name from a base64 encoded request parameter and writes the posted content to it with no path or extension validation, so a backend user holding core.edit.css on com_visforms can create a .php file anywhere the web server can write and reach remote code execution. The vendor also fixed arbitrary file deletion through path traversal with missing authorisation and missing CSRF protection, a bypass of the form edit authorisation that can redirect future form submissions to an attacker chosen mailbox, a bypass of the Joomla core.create permission, an unauthenticated verification mail and verification table amplification for arbitrary form IDs (the vulnerable AJAX endpoint sends verification mail for any form ID behind only a session token, which any visitor can obtain from a public page), and an external redirect through the return parameter on an invalid form submission. The arbitrary file write and the unauthenticated verification mail amplification were both confirmed present by reading the released packages on 2026-08-18. Fixed on the Joomla 6 branch in Visforms 6.2.1, released 13 August 2026. Update to 6.2.1 or later.
Affected versions: ≥ 6.0.0 and < 6.2.1
Full advisory: docs.joomla-6.visforms.vi-solutions.de
High
Visforms (com_visforms) 5.0.0 to below 5.6.4 - Authenticated Arbitrary File Write (RCE), Arbitrary File Delete, Permission Bypasses and Unauthenticated Mail Amplification
Visforms ships a set of flaws credited by vi-solutions to the security researcher Yukusawa18. The most serious is an arbitrary file write: the CSS editor in the administrator Vistools model takes its target file name from a base64 encoded request parameter and writes the posted content to it with no path or extension validation, so a backend user holding core.edit.css on com_visforms can create a .php file anywhere the web server can write and reach remote code execution. The vendor also fixed arbitrary file deletion through path traversal with missing authorisation and missing CSRF protection, a bypass of the form edit authorisation that can redirect future form submissions to an attacker chosen mailbox, a bypass of the Joomla core.create permission, an unauthenticated verification mail and verification table amplification for arbitrary form IDs (the vulnerable AJAX endpoint sends verification mail for any form ID behind only a session token, which any visitor can obtain from a public page), and an external redirect through the return parameter on an invalid form submission. The arbitrary file write and the unauthenticated verification mail amplification were both confirmed present by reading the released packages on 2026-08-18. Fixed on the Joomla 5 branch in Visforms 5.6.4, released 18 August 2026. Update to 5.6.4 or later.
Affected versions: ≥ 5.0.0 and < 5.6.4
Full advisory: docs.joomla-5.visforms.vi-solutions.de
High
Visforms (com_visforms) 4.x up to 4.4.3 - Authenticated Arbitrary File Write (RCE), Arbitrary File Delete, Permission Bypasses and Unauthenticated Mail Amplification, no fixed 4.x release
Visforms ships a set of flaws credited by vi-solutions to the security researcher Yukusawa18. The most serious is an arbitrary file write: the CSS editor in the administrator Vistools model takes its target file name from a base64 encoded request parameter and writes the posted content to it with no path or extension validation, so a backend user holding core.edit.css on com_visforms can create a .php file anywhere the web server can write and reach remote code execution. The vendor also fixed arbitrary file deletion through path traversal with missing authorisation and missing CSRF protection, a bypass of the form edit authorisation that can redirect future form submissions to an attacker chosen mailbox, a bypass of the Joomla core.create permission, an unauthenticated verification mail and verification table amplification for arbitrary form IDs (the vulnerable AJAX endpoint sends verification mail for any form ID behind only a session token, which any visitor can obtain from a public page), and an external redirect through the return parameter on an invalid form submission. The arbitrary file write and the unauthenticated verification mail amplification were both confirmed present by reading the released packages on 2026-08-18. There is no fixed 4.x release. The current and final 4.x release is Visforms 4.4.3 from 4 June 2024, and the vendor shipped the fixes on the 6.x branch (6.2.1, 13 August 2026) and the 5.x branch (5.6.4, 18 August 2026) only. The released 4.4.3 package was read on 2026-08-18 and still contains the unvalidated CSS editor file write and the ungated verification mail endpoint. Visforms 4.x runs on Joomla 4 and 5, so a site already on Joomla 5 can move to Visforms 5.6.4; a site still on Joomla 4 has no patched Visforms release available and should restrict who holds com_visforms permissions in the backend until one ships.
Affected versions: ≥ 4.0.0 and ≤ 4.4.3
Full advisory: vi-solutions.de
Visforms (com_visforms) 3.0.0 below 3.0.5 - SQL Injection (CVE-2023-23753)
Visforms Base Package for Joomla 3, versions 3.0.0 to below 3.0.5, is affected by an SQL injection vulnerability (CVE-2023-23753). Update to 3.0.5 or later.
Affected versions: ≥ 3.0.0 and < 3.0.5
Full advisory: nvd.nist.gov
Running Visforms on a site you manage?
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
CVE identifiers: CVE-2023-23753. Rules current as of 13 September 2026.