2026-07-26HIGHexploitedThe Joomla extension disclosure wave adds a cookie-forgery auth bypass, one anonymous request reaches Super User, and Super User means PHP
Joomla extension file-upload RCE wave
trend · trend:joomla-extension-file-upload-rce-wave single-source
A sustained wave of vulnerability disclosures in unrelated Joomla third-party extensions running since late June 2026, in which anonymous or near-anonymous single-request paths to full site compromise keep surfacing in widely-installed commercial components. It began as an arbitrary-file-upload-to-RCE cluster (CWE-434) surfaced by researcher mySites.guru via source-code audits: JoomShaper SP Page Builder (CVE-2026-48908), Joomlack Page Builder CK (CVE-2026-56290), Balbooa Forms (CVE-2026-56291), iCagenda (CVE-2026-48939), RSFiles! (CVE-2026-57827, unauthenticated, CVSS 10.0) and Phoca Download (CVE-2026-57828, authenticated, CVSS 9.0); several were CISA-KEV-listed within days, iCagenda after confirmed zero-day exploitation (mySites.guru, 2026-07-08/10). The wave has since broadened beyond that single flaw class and beyond one researcher: Balbooa Gridbox accepted a client-supplied cookie as proof of identity (CVE-2026-61425) and later let an anonymous visitor register straight into an administrator group (CVE-2026-65884/-65885, exploitation observed), and VulnCheck disclosed an unauthenticated PHP object injection reaching code execution in the Aimy Captcha-Less Form Guard anti-spam plugin (CVE-2026-65883, CWE-502). The through-line is the under-reviewed Joomla extension directory, not one CWE.
Coverage
9
first 2026-07-09 → last 2026-09-29
Latest activity
2026-09-29
The Joomla extension disclosure wave adds a cookie-forgery auth bypass, one anonymous request reaches Super…
Peak priority
high
7 high · 2 notable
Targets
public-sector
sectors: public-sector, technology, education · regions: europe, switzerland
Sources cited
20
5 hosts
Action items (19)
Do-now tasks recorded on the entries about Joomla extension file-upload RCE wave, newest first. Check the date before acting on an older one.
- Inventory Joomla sites for the Balbooa Gridbox page builder and update every one to 2.20.3.1, which also closes an unauthenticated blind SQL injection in the front-end blog author parameter present in every earlier build, 2.20.3 and 2.20.2.3 included. Anything below 2.20.2 is also exposed to the exploited follow-up batch, which 2.20.1 does not close, and the vulnerable code has shipped since the October 2025 release.2026-07-26CVE-2026-61425 +9
- On any site that ran Gridbox 2.20.1 or earlier while internet-reachable, review the Super User list and administrator-group members, remove accounts that entered an admin group through self-registration rather than an explicit administrative action, and review template files and the web root for changes, with particular attention to files written since 27 July.2026-07-26CVE-2026-61425 +9
- Upgrade Sourcerer to 16.0.0 immediately on every Joomla site, and treat any site that updated to 14.0.0, 14.0.1 or 15.0.0 between 17 and 26 August as having been exploitable the entire window regardless of what the extension manager reported; the CVE's own affected range was widened after the fact to admit this.2026-08-28CVE-2026-74253 +1
- Do not rely on HTML-escaping as a compensating control while awaiting the 16.0.0 upgrade, Sourcerer decodes HTML entities inside its own tags by design, so escaped input still executes.2026-08-28CVE-2026-74253 +1
- Upgrade iCagenda to 4.0.12 or later by manually downloading the release rather than trusting an automated update-status check, the Calendar module's own version stayed pinned at 4.0.7 through package releases 4.0.8-4.0.11, and iCagenda's own update feed had not yet been updated to list 4.0.12 as of 2026-08-28, so both the extension manager's package version and an automated update check can each independently report a vulnerable site as current.2026-08-28CVE-2026-67365
14 older action items
- Upgrade every YOOtheme ZOO (com_zoo) installation to 4.1.66 or later now, regardless of whether the front-end submission form is enabled, CVE-2026-74804 (unauthenticated SQL injection) is reachable on any site running ZOO at all. There is no fix for the 3.x line; treat any ZOO 3.x installation as permanently exposed and plan migration or removal.2026-08-28CVE-2026-74803 +4
- Audit images/zoo/uploads/ on every ZOO installation for any non-image file, especially .php, as a compromise check regardless of current patch level, the file-upload flaw (CVE-2026-74803) predates this week's disclosure across the entire 1.0.0–4.1.63 range.2026-08-28CVE-2026-74803 +4
- Query your Joomla estate for SP Page Builder and update every instance below 6.7.1; on any site that ran 6.7.0 or earlier while internet-reachable, treat the Joomla user table as read, force a password reset for all accounts and rotate the site secret, because the SQL injection needs no account and returns password hashes.2026-08-02CVE-2026-65766 +4
- Query the Joomla extension inventory of every site you run for Aimy Captcha-Less Form Guard and upgrade any instance below 20.1; an internet-wide scan will not find these for you, because the plugin only renders on the specific forms an administrator attached it to and never on a homepage.2026-08-01CVE-2026-65883
- Update RSFiles! (com_rsfiles) to ≥ 1.17.12 on every Joomla site now (this is unauthenticated RCE reachable by anyone, not a maintenance-window update) then check the component's web-root /downloads directory for stray .php/.phtml files and review admin accounts for tampering.2026-07-11CVE-2026-57827 +1
- Update Phoca Download (com_phocadownload) to ≥ 6.1.3; if the frontend member-upload feature was enabled (it is off by default), treat as a priority and hunt the user-upload folder for web shells. Disable member-upload where not required to remove the exposure entirely.2026-07-11CVE-2026-57827 +1
- As defense-in-depth against the whole wave, configure the web server to deny script execution in Joomla extension upload/download directories.2026-07-11CVE-2026-57827 +1
- Update iCagenda to ≥ 4.0.8 (current branch) or ≥ 3.9.15 (legacy branch) on every Joomla site now; unpublishing the component does not protect it; the submit endpoint and any uploaded files stay reachable.2026-07-10CVE-2026-48939
- On Joomla 6 sites assume pre-patch compromise: hunt for any file that should not exist under images/icagenda/frontend/attachments/ (a .php file there is a web shell until proven otherwise), and if found, treat the whole site as compromised and rotate Joomla secrets.2026-07-10CVE-2026-48939
- On Joomla 2.5–5 sites, check the event-submission queue for anonymously-created unapproved events as a sign the access bypass was used.2026-07-10CVE-2026-48939
- Inventory every Joomla site running Balbooa Forms and update all installs to 2.4.1 or later immediately, do not wait for a maintenance window; the flaw is being actively exploited.2026-07-09CVE-2026-56291
- Treat any site that ran 2.4.0 or earlier while exposed as possibly compromised: check images/baforms/uploads/ (and other per-component upload folders) for unexpected .php/.phtml files and check Joomla for unexpected Super User accounts.2026-07-09CVE-2026-56291
- At the web-server layer, deny PHP execution inside upload-only directories (nginx location block / Apache php_admin_flag engine off on images/ and media/ subpaths) regardless of vendor patch status, this closes the whole recurring bug class, not one component.2026-07-09CVE-2026-56291
- Hunt access logs for POST requests to index.php?option=com_baforms&task=form.uploadAttachmentFile returning HTTP 200 followed by a GET to a newly created executable file under the upload directory.2026-07-09CVE-2026-56291
Defender insights
What each entry about Joomla extension file-upload RCE wave tells a defender to do, newest first.
Latest update · triage
Triage
Triage
Triage
Triage
Triage
3 earlier entries carry guidance too, listed under the story timeline below.
Story timeline
- 2026-08-28YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix
- 2026-08-28Sourcerer for Joomla: unauthenticated RCE exploited in the wild since before a working fix existed; the vendor's first two patches did not close it, and the CVE was re-scoped in place to widen the affected range
- 2026-08-28iCagenda Calendar module for Joomla: unauthenticated SQL injection via com_ajax needs no session, token or account (CVE-2026-67365, CVSS 9.2), and the vulnerable module's own version number does not track the package version
- 2026-08-02CVE-2026-65766 and CVE-2026-65879, SP Page Builder for Joomla: a CSRF token Joomla hands to anonymous visitors is the only guard on an ORDER BY injection, plus a shipped-in-source shared secret that opens a mail relay
- 2026-08-01CVE-2026-65883, Aimy Captcha-Less Form Guard for Joomla: the anti-spam token is deserialized before any check, and the XOR keystream ships in the same page (CVSS 9.8)
- 2026-07-26CVE-2026-61425, Balbooa Gridbox for Joomla: a client-supplied cookie is accepted as proof of identity, giving anonymous Super User access
- 2026-07-11Joomla file-upload RCE wave adds RSFiles! (CVE-2026-57827, unauth, CVSS 10.0) and Phoca Download (CVE-2026-57828, CVSS 9.0)
- 2026-07-10CVE-2026-48939, iCagenda for Joomla: unauthenticated file-upload-to-RCE, exploited as a zero-day, added to CISA KEV (CVSS 4.0 10.0)
- 2026-07-09CVE-2026-56291, Balbooa Forms for Joomla: unauthenticated file-upload RCE exploited as a zero-day (CVSS 10.0)
Hunting pivots
CVEs (exploited first)
CVE-2026-48939CVE-2026-56291CVE-2026-65884CVE-2026-65885CVE-2026-65887CVE-2026-65888CVE-2026-74253CVE-2026-57827CVE-2026-57828CVE-2026-61425CVE-2026-62415CVE-2026-63047CVE-2026-64796CVE-2026-65759CVE-2026-65760CVE-2026-65761CVE-2026-65766CVE-2026-65876CVE-2026-65877CVE-2026-65878CVE-2026-65879CVE-2026-65883CVE-2026-67365CVE-2026-74803
Affected products
Aimy Captcha-Less Form GuardBalbooa GridboxBalbooa Gridbox for JoomlaJoomShaper EasyStoreJoomShaper SP Page BuilderJoomla Events BookingJoomla Membership ProJoomliC iCagendaPhoca Download for JoomlaRSFiles! for JoomlaSourcerer for Joomla (plg_system_sourcerer, plg_editors-xtd_sourcerer)YOOtheme Pro for JoomlaYOOtheme ZOO (com_zoo)iCagenda (mod_icagenda_calendar) for Joomla
ATT&CK techniques (4 across 3 tactics)
4 techniques observed across 9 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter
- PersistenceCreate Account: Local Account · Server Software Component: Web Shell
Initial Access TA0001
T1190Exploit Public-Facing Application×9
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-08-28/yootheme-zoo-joomla-unauth-file-upload-rce-sqli · 2026-08-28/sourcerer-joomla-unauth-rce-patch-bypass-of-patch-bypass · 2026-08-28/icagenda-joomla-calendar-module-unauth-sqli · 2026-08-02/sp-page-builder-cve-2026-65766-preauth-sqli-mail-relay · 2026-08-01/aimy-captcha-joomla-cve-2026-65883-object-injection-rce · 2026-07-26/joomla-gridbox-cookie-forged-super-user-auth-bypass-wave +3 more · ATT&CK page ↗
Execution TA0002
T1059Command and Scripting Interpreter×1
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
Evidence: 2026-08-28/sourcerer-joomla-unauth-rce-patch-bypass-of-patch-bypass · ATT&CK page ↗
Persistence TA0003
T1136.001Create Account: Local Account×1
Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.
Evidence: 2026-07-26/joomla-gridbox-cookie-forged-super-user-auth-bypass-wave · ATT&CK page ↗
T1505.003Server Software Component: Web Shell×5
Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.
Evidence: 2026-08-28/yootheme-zoo-joomla-unauth-file-upload-rce-sqli · 2026-07-26/joomla-gridbox-cookie-forged-super-user-auth-bypass-wave · 2026-07-11/joomla-rsfiles-phoca-file-upload-rce-cve-2026-57827-57828 · 2026-07-10/cve-2026-48939-icagenda-joomla-unauth-file-upload-rce-kev · 2026-07-09/cve-2026-56291-balbooa-forms-joomla-unauth-file-upload-rce · ATT&CK page ↗
Entries about Joomla extension file-upload RCE wave (9)
Earlier coverage (6)
YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fixmySites.guru found three unauthenticated flaws in YOOtheme ZOO (com_zoo) for Joomla, affecting every version 1.0.0–4.1.63: CVE-2026-74803 (CVSS 10.0) is an arbitrary-file-upload-to-RCE via a Content-Type-only validation bypass in the front-end submission form; CVE-2026-74804 (CVSS 9.3) is a precondition-free unauthenticated SQL injection reachable even with no submission form configured. Fixed in ZOO 4.1.66 after two follow-up releases; no fix exists for the 3.x line.CVE-2026-65766 and CVE-2026-65879, SP Page Builder for Joomla: a CSRF token Joomla hands to anonymous visitors is the only guard on an ORDER BY injection, plus a shipped-in-source shared secret that opens a mail relaymySites.guru disclosed four vulnerabilities in JoomShaper's SP Page Builder 6.7.0 on 2026-07-27, all fixed the same day in 6.7.1, with four CVEs assigned by the Joomla CNA and a fifth (CVE-2026-65876, 9.2, an unauthenticated SQL injection the discloser did not report or test) covering the same versions, so 6.7.1 fixes five issues, not four. CVE-2026-65766 (Joomla CNA, CVSS 4.0 9.2) places a request value straight into the ORDER BY clause of the Dynamic Content endpoint's query; the only control in front of it is a Joomla CSRF token, which Joomla issues to every anonymous visitor on page load, so a scripted attacker fetches a token and replays it, effectively pre-authentication SQL injection that reads the entire Joomla database, password hashes included. CVE-2026-65879 is a design flaw rather than a slip: the contact-form addons sign the configured recipient address with a secret hardcoded identically into every shipped copy of the extension, so anyone holding the extension can forge a signature and send mail to any recipient with a spoofed sender through the site's own mail server. The same extension's unauthenticated icon-upload zero-day was being exploited in the wild in June 2026.CVE-2026-65883, Aimy Captcha-Less Form Guard for Joomla: the anti-spam token is deserialized before any check, and the XOR keystream ships in the same page (CVSS 9.8)VulnCheck disclosed CVE-2026-65883 on 2026-07-30, an unauthenticated PHP object injection in the Aimy Captcha-Less Form Guard plugin for Joomla, versions 18.0 through 20.0 and fixed in 20.1. The plugin base64-decodes a hidden form token, runs it through a repeating-key XOR and passes the result straight to unserialize() with no signature and no allowed_classes, and because the plugin renders a ciphertext for that same keystream in every protected form, the key is recoverable and the object forgeable. On Joomla 3.9 through 5.2.1 it chains through a core gadget to remote code execution as the web user. No exploitation is reported, but three other unauthenticated Joomla extension flaws disclosed this year were exploited in the wild and KEV-listed.Joomla file-upload RCE wave adds RSFiles! (CVE-2026-57827, unauth, CVSS 10.0) and Phoca Download (CVE-2026-57828, CVSS 9.0)Two more Joomla third-party extensions from the same researcher-driven disclosure wave patched arbitrary-file-upload-to-RCE flaws on 2026-07-10: RSFiles! (com_rsfiles) up to 1.17.11 lets any unauthenticated visitor upload and execute a .php file in its web-root downloads folder (CVE-2026-57827, CVSS 4.0 10.0, fixed 1.17.12), and Phoca Download (com_phocadownload) up to 6.1.2 lets a logged-in member bypass the file-type allow-list on its non-default member-upload feature (CVE-2026-57828, CVSS 4.0 9.0, fixed 6.1.3). No public PoC and no confirmed exploitation of these two yet, but earlier members of this exact CWE-434 wave reached CISA KEV within days; any Swiss/EU municipal or public-sector Joomla site running these extensions should update now and hunt for web shells.CVE-2026-48939, iCagenda for Joomla: unauthenticated file-upload-to-RCE, exploited as a zero-day, added to CISA KEV (CVSS 4.0 10.0)CISA added CVE-2026-48939 to its Known Exploited Vulnerabilities catalog on 2026-07-10. The flaw in iCagenda, a widely deployed Joomla events/calendar extension, lets an unauthenticated visitor upload a PHP web shell through the public event-submission form; on Joomla 6 this yields remote code execution, and the underlying access-control bypass affects every Joomla version. It was exploited in the wild before a patch existed. Any Joomla site running iCagenda ≤ 4.0.7 (or ≤ 3.9.14 on the legacy branch) must update now and hunt for pre-patch compromise, relevant to the many Swiss and European municipal and public-sector sites built on Joomla.CVE-2026-56291, Balbooa Forms for Joomla: unauthenticated file-upload RCE exploited as a zero-day (CVSS 10.0)Balbooa Forms (the com_baforms Joomla component) up to and including 2.4.0 exposed its frontend attachment-upload handler to any anonymous visitor with no authentication, no CSRF token, and no file-extension allow-list, allowing a .php upload to be written into a web-served directory and executed, unauthenticated RCE (CWE-434). It was exploited as a zero-day before the 2.4.1 fix (9 July 2026) and attacks continue against unpatched sites. Anyone running Joomla with Balbooa Forms should update to 2.4.1 now and check for tampering.
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- Aimy Captcha-Less Form Guard×1
- Aimy Captcha-Less Form Guard (Joomla plugin), unauthenticated PHP object injection to RCE, CVSS 9.8; fixed in 20.1×1
- Balbooa Forms for Joomla (com_baforms) unauthenticated file-upload RCE (CWE-434, CVSS 4.0 10.0), zero-day exploited pre-patch; 3rd Joomla-extension file-upload RCE in the 2026-06/07 wave×1
- Balbooa Gridbox×1
- Balbooa Gridbox for Joomla×1
- Balbooa Gridbox for Joomla, authenticated arbitrary file upload; becomes unauthenticated RCE chained with CVE-2026-65884 because the attacker can create the required account; CVSS 4.0 9.4 (CWE-434, Joomla CNA), exploit maturity Attacked; affected 1.0.0-2.20.1, fixed 2.20.2×1
- Balbooa Gridbox for Joomla, password reset of any non-Super-User account (CVSS 4.0 10.0), exploit maturity Attacked; fixed in 2.20.2×1
- Balbooa Gridbox for Joomla, social-login method logs the caller in as any user (CVSS 4.0 10.0), exploit maturity Attacked; fixed in 2.20.2×1
Where this entity is cited
Source distribution
- mysites.guru14 (70%)
- balbooa.com2 (10%)
- cisa.gov2 (10%)
- rsjoomla.com1 (5%)
- vulncheck.com1 (5%)
All cited sources (20)
- balbooa.comBalbooahttps://www.balbooa.com/blog/gridbox/gridbox-2-20-2-security-release
- balbooa.comBalbooa (vendor changelog)https://www.balbooa.com/help/joomla-forms-documentation/basics/changelog
- cisa.govCISAhttps://www.cisa.gov/news-events/alerts/2026/07/10/cisa-adds-two-known-exploited-vulnerabilities-catalog
- cisa.govCISA KEVhttps://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
- mysites.gurumySites.guruhttps://mysites.guru/blog/balbooa-forms-unauthenticated-file-upload-flaw/
- mysites.gurumySites.guruhttps://mysites.guru/blog/easystore-security-disclosure/
- mysites.gurumySites.guruhttps://mysites.guru/blog/events-booking-invoice-idor/
- mysites.gurumySites.guruhttps://mysites.guru/blog/gridbox-23-critical-vulnerabilities/
- mysites.gurumySites.guruhttps://mysites.guru/blog/gridbox-author-sql-injection/
- mysites.gurumySites.guruhttps://mysites.guru/blog/gridbox-critical-authentication-bypass/
- mysites.gurumySites.guruhttps://mysites.guru/blog/icagenda-calendar-module-sql-injection/
- mysites.gurumySites.guruhttps://mysites.guru/blog/icagenda-zero-day-file-upload-rce/
- mysites.gurumySites.guruhttps://mysites.guru/blog/membership-pro-unauthenticated-file-upload/
- mysites.gurumySites.guruhttps://mysites.guru/blog/phoca-download-authenticated-file-upload-rce/
- mysites.gurumySites.guruhttps://mysites.guru/blog/rsfiles-unauthenticated-file-upload-rce/
- mysites.gurumySites.guruhttps://mysites.guru/blog/sourcerer-14-unverified-content-php-execution/
- mysites.gurumySites.guruhttps://mysites.guru/blog/sp-page-builder-sql-injection-mail-relay-disclosure/
- mysites.gurumySites.guruhttps://mysites.guru/blog/zoo-unauthenticated-file-upload-rce/
- rsjoomla.comRSJoomla! (vendor)https://www.rsjoomla.com/blog/view/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html
- vulncheck.comVulnCheckhttps://www.vulncheck.com/blog/aimy-captcha-less-form-guard-object-injection