CTIPilot
AI-generated · no human review · verify critical claims against the linked source. how it works →

Joomla extension file-upload RCE wave

trend · trend:joomla-extension-file-upload-rce-wave single-source

A sustained wave of vulnerability disclosures in unrelated Joomla third-party extensions running since late June 2026, in which anonymous or near-anonymous single-request paths to full site compromise keep surfacing in widely-installed commercial components. It began as an arbitrary-file-upload-to-RCE cluster (CWE-434) surfaced by researcher mySites.guru via source-code audits: JoomShaper SP Page Builder (CVE-2026-48908), Joomlack Page Builder CK (CVE-2026-56290), Balbooa Forms (CVE-2026-56291), iCagenda (CVE-2026-48939), RSFiles! (CVE-2026-57827, unauthenticated, CVSS 10.0) and Phoca Download (CVE-2026-57828, authenticated, CVSS 9.0); several were CISA-KEV-listed within days, iCagenda after confirmed zero-day exploitation (mySites.guru, 2026-07-08/10). The wave has since broadened beyond that single flaw class and beyond one researcher: Balbooa Gridbox accepted a client-supplied cookie as proof of identity (CVE-2026-61425) and later let an anonymous visitor register straight into an administrator group (CVE-2026-65884/-65885, exploitation observed), and VulnCheck disclosed an unauthenticated PHP object injection reaching code execution in the Aimy Captcha-Less Form Guard anti-spam plugin (CVE-2026-65883, CWE-502). The through-line is the under-reviewed Joomla extension directory, not one CWE.

Coverage
9
first 2026-07-09 → last 2026-09-29
Latest activity
2026-09-29
The Joomla extension disclosure wave adds a cookie-forgery auth bypass, one anonymous request reaches Super…
Peak priority
high
7 high · 2 notable
Targets
public-sector
sectors: public-sector, technology, education · regions: europe, switzerland
Sources cited
20
5 hosts

Action items (19)

Do-now tasks recorded on the entries about Joomla extension file-upload RCE wave, newest first. Check the date before acting on an older one.

  • Inventory Joomla sites for the Balbooa Gridbox page builder and update every one to 2.20.3.1, which also closes an unauthenticated blind SQL injection in the front-end blog author parameter present in every earlier build, 2.20.3 and 2.20.2.3 included. Anything below 2.20.2 is also exposed to the exploited follow-up batch, which 2.20.1 does not close, and the vulnerable code has shipped since the October 2025 release.
    2026-07-26CVE-2026-61425 +9
  • On any site that ran Gridbox 2.20.1 or earlier while internet-reachable, review the Super User list and administrator-group members, remove accounts that entered an admin group through self-registration rather than an explicit administrative action, and review template files and the web root for changes, with particular attention to files written since 27 July.
    2026-07-26CVE-2026-61425 +9
  • Upgrade Sourcerer to 16.0.0 immediately on every Joomla site, and treat any site that updated to 14.0.0, 14.0.1 or 15.0.0 between 17 and 26 August as having been exploitable the entire window regardless of what the extension manager reported; the CVE's own affected range was widened after the fact to admit this.
    2026-08-28CVE-2026-74253 +1
  • Do not rely on HTML-escaping as a compensating control while awaiting the 16.0.0 upgrade, Sourcerer decodes HTML entities inside its own tags by design, so escaped input still executes.
    2026-08-28CVE-2026-74253 +1
  • Upgrade iCagenda to 4.0.12 or later by manually downloading the release rather than trusting an automated update-status check, the Calendar module's own version stayed pinned at 4.0.7 through package releases 4.0.8-4.0.11, and iCagenda's own update feed had not yet been updated to list 4.0.12 as of 2026-08-28, so both the extension manager's package version and an automated update check can each independently report a vulnerable site as current.
    2026-08-28CVE-2026-67365
14 older action items
  • Upgrade every YOOtheme ZOO (com_zoo) installation to 4.1.66 or later now, regardless of whether the front-end submission form is enabled, CVE-2026-74804 (unauthenticated SQL injection) is reachable on any site running ZOO at all. There is no fix for the 3.x line; treat any ZOO 3.x installation as permanently exposed and plan migration or removal.
    2026-08-28CVE-2026-74803 +4
  • Audit images/zoo/uploads/ on every ZOO installation for any non-image file, especially .php, as a compromise check regardless of current patch level, the file-upload flaw (CVE-2026-74803) predates this week's disclosure across the entire 1.0.0–4.1.63 range.
    2026-08-28CVE-2026-74803 +4
  • Query your Joomla estate for SP Page Builder and update every instance below 6.7.1; on any site that ran 6.7.0 or earlier while internet-reachable, treat the Joomla user table as read, force a password reset for all accounts and rotate the site secret, because the SQL injection needs no account and returns password hashes.
    2026-08-02CVE-2026-65766 +4
  • Query the Joomla extension inventory of every site you run for Aimy Captcha-Less Form Guard and upgrade any instance below 20.1; an internet-wide scan will not find these for you, because the plugin only renders on the specific forms an administrator attached it to and never on a homepage.
    2026-08-01CVE-2026-65883
  • Update RSFiles! (com_rsfiles) to ≥ 1.17.12 on every Joomla site now (this is unauthenticated RCE reachable by anyone, not a maintenance-window update) then check the component's web-root /downloads directory for stray .php/.phtml files and review admin accounts for tampering.
    2026-07-11CVE-2026-57827 +1
  • Update Phoca Download (com_phocadownload) to ≥ 6.1.3; if the frontend member-upload feature was enabled (it is off by default), treat as a priority and hunt the user-upload folder for web shells. Disable member-upload where not required to remove the exposure entirely.
    2026-07-11CVE-2026-57827 +1
  • As defense-in-depth against the whole wave, configure the web server to deny script execution in Joomla extension upload/download directories.
    2026-07-11CVE-2026-57827 +1
  • Update iCagenda to ≥ 4.0.8 (current branch) or ≥ 3.9.15 (legacy branch) on every Joomla site now; unpublishing the component does not protect it; the submit endpoint and any uploaded files stay reachable.
    2026-07-10CVE-2026-48939
  • On Joomla 6 sites assume pre-patch compromise: hunt for any file that should not exist under images/icagenda/frontend/attachments/ (a .php file there is a web shell until proven otherwise), and if found, treat the whole site as compromised and rotate Joomla secrets.
    2026-07-10CVE-2026-48939
  • On Joomla 2.5–5 sites, check the event-submission queue for anonymously-created unapproved events as a sign the access bypass was used.
    2026-07-10CVE-2026-48939
  • Inventory every Joomla site running Balbooa Forms and update all installs to 2.4.1 or later immediately, do not wait for a maintenance window; the flaw is being actively exploited.
    2026-07-09CVE-2026-56291
  • Treat any site that ran 2.4.0 or earlier while exposed as possibly compromised: check images/baforms/uploads/ (and other per-component upload folders) for unexpected .php/.phtml files and check Joomla for unexpected Super User accounts.
    2026-07-09CVE-2026-56291
  • At the web-server layer, deny PHP execution inside upload-only directories (nginx location block / Apache php_admin_flag engine off on images/ and media/ subpaths) regardless of vendor patch status, this closes the whole recurring bug class, not one component.
    2026-07-09CVE-2026-56291
  • Hunt access logs for POST requests to index.php?option=com_baforms&task=form.uploadAttachmentFile returning HTTP 200 followed by a GET to a newly created executable file under the upload directory.
    2026-07-09CVE-2026-56291

Defender insights

What each entry about Joomla extension file-upload RCE wave tells a defender to do, newest first.

2026-07-26HIGHexploitedThe Joomla extension disclosure wave adds a cookie-forgery auth bypass, one anonymous request reaches Super User, and Super User means PHP

Latest update · triage

2026-08-28HIGHexploitedEvery site that 'patched' Sourcerer between 17 and 26 August was exploitable the entire time, and its own extension manager said otherwise

Triage

2026-08-28NOTABLEA Joomla events extension's bundled Calendar module can stay vulnerable for three package releases without the extension manager ever showing it

Triage

2026-08-28HIGHA Joomla content extension trusts the client's own Content-Type header to decide what an anonymous visitor can upload

Triage

2026-08-02HIGHThe Joomla page builder whose icon-upload zero-day was exploited in June ships four more flaws, one reads the whole database without an account

Triage

2026-08-01NOTABLEA Joomla anti-spam plugin hands unserialize() an attacker-controlled object on every public form, reaching code execution on Joomla cores up to 5.2.1

Triage

3 earlier entries carry guidance too, listed under the story timeline below.

Story timeline

  1. 2026-08-28YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix
    trending-vulnerabilitiesA Joomla content extension trusts the client's own Content-Type header to decide what an anonymous visitor can upload
  2. 2026-08-28Sourcerer for Joomla: unauthenticated RCE exploited in the wild since before a working fix existed; the vendor's first two patches did not close it, and the CVE was re-scoped in place to widen the affected range
    trending-vulnerabilitiesEvery site that 'patched' Sourcerer between 17 and 26 August was exploitable the entire time, and its own extension manager said otherwise
  3. 2026-08-28iCagenda Calendar module for Joomla: unauthenticated SQL injection via com_ajax needs no session, token or account (CVE-2026-67365, CVSS 9.2), and the vulnerable module's own version number does not track the package version
    trending-vulnerabilitiesA Joomla events extension's bundled Calendar module can stay vulnerable for three package releases without the extension manager ever showing it
  4. 2026-08-02CVE-2026-65766 and CVE-2026-65879, SP Page Builder for Joomla: a CSRF token Joomla hands to anonymous visitors is the only guard on an ORDER BY injection, plus a shipped-in-source shared secret that opens a mail relay
    trending-vulnerabilitiesThe Joomla page builder whose icon-upload zero-day was exploited in June ships four more flaws, one reads the whole database without an account
  5. 2026-08-01CVE-2026-65883, Aimy Captcha-Less Form Guard for Joomla: the anti-spam token is deserialized before any check, and the XOR keystream ships in the same page (CVSS 9.8)
    trending-vulnerabilitiesA Joomla anti-spam plugin hands unserialize() an attacker-controlled object on every public form, reaching code execution on Joomla cores up to 5.2.1
  6. 2026-07-26CVE-2026-61425, Balbooa Gridbox for Joomla: a client-supplied cookie is accepted as proof of identity, giving anonymous Super User access
    trending-vulnerabilitiesThe Joomla extension disclosure wave adds a cookie-forgery auth bypass, one anonymous request reaches Super User, and Super User means PHP
  7. 2026-07-11Joomla file-upload RCE wave adds RSFiles! (CVE-2026-57827, unauth, CVSS 10.0) and Phoca Download (CVE-2026-57828, CVSS 9.0)
    trending-vulnerabilitiesTwo more Joomla extensions patch file-upload-to-RCE flaws, RSFiles! is reachable with no login at all (CVSS 10.0)
  8. 2026-07-10CVE-2026-48939, iCagenda for Joomla: unauthenticated file-upload-to-RCE, exploited as a zero-day, added to CISA KEV (CVSS 4.0 10.0)
    trending-vulnerabilitiesCISA KEV-lists an actively-exploited unauth RCE in the iCagenda Joomla extension, RCE hits Joomla 6, auth bypass hits all versions
  9. 2026-07-09CVE-2026-56291, Balbooa Forms for Joomla: unauthenticated file-upload RCE exploited as a zero-day (CVSS 10.0)
    trending-vulnerabilitiesBalbooa patches an actively-exploited unauthenticated file-upload RCE in its Joomla Forms extension, the third such flaw in the ecosystem in two weeks
ATT&CK techniques (4 across 3 tactics)

4 techniques observed across 9 entries about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)

  • Initial AccessExploit Public-Facing Application
  • ExecutionCommand and Scripting Interpreter
  • PersistenceCreate Account: Local Account · Server Software Component: Web Shell

Initial Access TA0001

T1190Exploit Public-Facing Application×9

Execution TA0002

T1059Command and Scripting Interpreter×1

Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.

Evidence: 2026-08-28/sourcerer-joomla-unauth-rce-patch-bypass-of-patch-bypass · ATT&CK page ↗

Persistence TA0003

T1136.001Create Account: Local Account×1

Adversaries may create a local account to maintain access to victim systems. Local accounts are those configured by an organization for use by users, remote support, services, or for administration on a single system or service.

Evidence: 2026-07-26/joomla-gridbox-cookie-forged-super-user-auth-bypass-wave · ATT&CK page ↗

T1505.003Server Software Component: Web Shell×5

Adversaries may backdoor web servers with web shells to establish persistent access to systems. A Web shell is a Web script that is placed on an openly accessible Web server to allow an adversary to access the Web server as a gateway into a network. A Web shell may provide a set of functions to execute or a command-line interface on the system that hosts the Web server.

Evidence: 2026-08-28/yootheme-zoo-joomla-unauth-file-upload-rce-sqli · 2026-07-26/joomla-gridbox-cookie-forged-super-user-auth-bypass-wave · 2026-07-11/joomla-rsfiles-phoca-file-upload-rce-cve-2026-57827-57828 · 2026-07-10/cve-2026-48939-icagenda-joomla-unauth-file-upload-rce-kev · 2026-07-09/cve-2026-56291-balbooa-forms-joomla-unauth-file-upload-rce · ATT&CK page ↗

Entries about Joomla extension file-upload RCE wave (9)

2026-07-26 · view entry permalink →

HIGHCVE-2026-61425 +9exploitedupdatedNATOB2

The Joomla third-party-extension disclosure wave covered here since early July has been a file-upload story: unauthenticated uploads reaching code execution, several of which were weaponised and CISA-KEV-listed within days of disclosure. The batch mySites.guru published between 2026-07-20 and 2026-07-23 adds a different and more direct failure. In Balbooa's Gridbox page builder, "A critical unauthenticated authentication bypass in Gridbox let anyone become a Super User on a Joomla site by setting a single browser cookie" (mySites.guru, 2026-07-20). The extension treats a client-supplied cookie value as proof of identity rather than as an assertion to be validated against server-side session state, so an anonymous requester who places an administrator's username in that cookie is served the site as that administrator, no password, no login form, no pre-existing session. Because a Joomla Super User can edit templates, and templates are PHP, the practical outcome is code execution on the web server from a single unauthenticated request. Gridbox 2.20.1 fixes it; the vulnerable code had shipped since the previous release in October 2025, roughly nine months of exposure.

The rest of the week's batch is the same research campaign continuing on its original axis, with two flaws that matter beyond the site itself. EasyStore for Joomla carried an unauthenticated SQL injection able to read the whole site database (CVE-2026-65761, scored 9.3 by the Joomla CNA) plus an order-forgery flaw (CVE-2026-65759, 8.7) where "An anonymous request to the order-repayment endpoint could mark any order paid with no login, no token, and no contact with any payment gateway" (mySites.guru, 2026-07-23), fixed in 2.0.2. Events Booking exposed invoices containing personal and financial data to anonymous requests that simply walked sequential identifiers, fixed in 5.8.2 (mySites.guru, 2026-07-21). Membership Pro's unauthenticated upload was initially disputed by the vendor, the researcher records that "The vendor called it 'not a critical security issue.' The Joomla CNA disagreed" and it was assigned CVE-2026-62415 at 9.1 critical, fixed in Membership Pro 4.6.2 (mySites.guru, 2026-07-21).

There is no public exploitation signal for any of these: the researcher withholds the exact cookie name, endpoints and proof-of-concept code under a fix-first policy. The reason to act ahead of the routine extension-update cycle is the wave's own track record rather than current telemetry, earlier members of this same disclosure series moved from publication to confirmed in-the-wild exploitation within days once the mechanism became public, and a cookie-forgery bypass is trivially rediscovered by anyone who diffs the 2.20.1 release against its predecessor.

Triage: a cookie-forgery bypass leaves little at the network layer to distinguish it; the request is well-formed and returns HTTP 200. The observable is the mismatch between authentication and privilege: administrative actions in Joomla's action log attributed to a Super User account with no preceding successful login event for that account, and no session-establishment record. Legitimate administrator activity is preceded by an authentication event from a consistent source; forged-cookie access produces privileged actions that appear without one. On sites running affected Gridbox versions, template-file modification timestamps postdating the October 2025 release, with no corresponding administrator login, are the artefacts worth reviewing.

A critical unauthenticated authentication bypass in Gridbox let anyone become a Super User on a Joomla site by setting a single browser cookie

An anonymous request to the order-repayment endpoint could mark any order paid with no login, no token, and no contact with any payment gateway.

Every one lists the affected range as 1.0.0 to 2.20.1, which is every Gridbox release there has ever been up to the fix, and four have the exploit maturity Attacked with an urgency of Red, the CVE record’s own way of saying this is being used against real sites rather than sitting as a theoretical risk.

the registration handler adds the default group to whatever groups the visitor asks for, instead of replacing them. So anyone can register a normal account and place themselves straight into an administrator group.

We have the server access logs showing the exploitation requests arriving, and connected sites where the accounts are already planted. On one connected Joomla site our rogue admin check is holding 92 planted accounts right now

mySites.guru 2026-07-20
Updaterun 2026-07-31T0409Z-intelactionsaffected_productscvesevidenceprioritysourcestagstechniquesbody

The earlier entry covered CVE-2026-61425, the Gridbox flaw that accepted a client-supplied cookie as proof of identity, fixed in 2.20.1. Balbooa's response was to commission the same researcher to audit the whole component, and that audit found 23 further vulnerabilities in this one extension (mySites.guru, 2026-07-29). The delta that matters is that 2.20.1 (the version the previous entry pointed operators at) is itself vulnerable to a worse flaw than the one it fixed, and that flaw is being exploited.

CVE-2026-65884 carries a CVSS 4.0 base score of 10.0 for a reason that requires no exploit skill at all: the registration handler adds the usergroup IDs supplied in the request to the default group rather than replacing them, so an anonymous visitor can register an ordinary account and place it directly into an administrator group. The researcher describes the defect precisely: the registration handler "adds the default group to whatever groups the visitor asks for, instead of replacing them," so "anyone can register a normal account and place themselves straight into an administrator group" (mySites.guru, 2026-07-29). CVE-2026-65885, scored 9.4, is an authenticated arbitrary file upload, and it becomes remote code execution when chained with the first because the attacker can create the account the upload requires. Both published records give the affected range as 1.0.0 to 2.20.1 (every version the extension has ever shipped up to the fix) and both are marked with an exploit maturity of attacked and an urgency of red by the Joomla CNA that assigned them (mySites.guru, 2026-07-29).

Exploitation is not an inference. The researcher reports holding server access logs showing the exploitation requests arriving and describes 92 planted administrator accounts on a single connected Joomla site, created in batches from 27 July, with usernames following one generator's pattern of a fixed prefix plus a few hex characters paired to matching webmail addresses (mySites.guru, 2026-07-29). Balbooa's own release page corroborates attack traffic indirectly, referring to a recent increase in automated attacks and telling customers to remove the temporary web-server rules it had advised adding to block attacks against Gridbox endpoints (Balbooa, 2026-07-29).

Getting to a fixed build took three attempts, which is itself operationally relevant for anyone who applied an interim Gridbox update this month. The researcher's account of the coordinated-disclosure process records that the vendor's first proposed fix left several reported findings live, including an anonymous SQL injection returning password hashes that had been patched at only one of several identical reachable entry points, and that the second closed that and the actively-exploited routes but still left a forgeable payment-gateway callback signature and a SQL injection reachable by a low-privilege authenticated user (mySites.guru, 2026-07-29). Only 2.20.2, released 2026-07-29, closes all of it, and the vendor states the build was given to the reporting researcher for independent verification before release (Balbooa, 2026-07-29). The remaining 21 findings are described only by shape, with nine further CVE IDs reserved but unpublished, so the public picture of this component's exposure is not yet complete.

Detection. Both halves of the chain leave records in places most Joomla operators already keep. For the privilege escalation, the artifact is a user account whose administrator-group membership was established at creation time rather than by a later administrative change, visible in the user table and in Joomla's own action logs as a registration event that produced an elevated account, with no corresponding admin action. Cluster it by timing: automated abuse of this flaw produces accounts in batches minutes apart, not the trickle of genuine sign-ups. For the upload half, the signal is a file appearing in a web-reachable directory with a server-executable extension, written by the web server user, followed by requests to that path from a small number of sources, and in web-server access logs, POST requests to the extension's registration and upload endpoints from addresses with no prior browsing history on the site.

Triage: a public Joomla site with open registration collects spam accounts constantly, so a new unrecognised user is not the signal. The discriminator is the group membership: ordinary registration spam lands in the default registered-users group and stays there, while these accounts sit in an administrator group from the moment they were created. Any self-registered account holding administrative rights on a Gridbox site should be treated as planted rather than misconfigured.

Updaterun 2026-09-29T2134Z-auditevidencecvessourcing_notesummaryverificationactionssourcesbody

All eleven CVE records the Joomla CNA assigned to the Gridbox 2.20.2 batch have now published. Every one lists Gridbox 1.0.0 to 2.20.1 as affected, seven are rated Critical, and four carry the exploit maturity Attacked with an urgency of Red (mySites.guru, revised since). Two of the four are new to this entry and both are CVSS 4.0 10.0: CVE-2026-65887, a password-reset method that resets any account's password and logs the attacker in as that user, Super Users excepted, and CVE-2026-65888, a social-login method that logs the caller in as any user on the site. mySites.guru reports the exploitation as seen in server access logs and on compromised sites, and the Joomla Security Strike Team reported at least three of the issues exploited on 29 July. The fix for that exploited set is Gridbox 2.20.2. On a site that ran an earlier build while internet-facing, unexpected password resets and social-login sessions for existing accounts belong in the same review as the attacker-registered administrator accounts described above.

Balbooa has shipped three releases since 2.20.2. Version 2.20.2.3 (10 August) is titled "Bug Fixes and Security Hardening" and touches the media manager's access controls, internal path validation and the password-recovery flow, with no CVE, severity or affected range. mySites.guru has not audited it and notes that three of those areas overlap flaws recorded as fixed in 2.20.2 (mySites.guru, revised since). Version 2.20.3.1 (21 September) fixes an unauthenticated time-based blind SQL injection in the front-end blog author parameter, which went into a database query without being cast to a number. Every build below 2.20.3.1 is affected, 2.20.3 and 2.20.2.3 included, and there is no CVE or CVSS score yet. The vendor filed it as security hardening, and the flaw was reported by Studio Przy Lesie and identified by CERT Polska (mySites.guru, 2026-09-21). No exploitation of it has been reported. The version to be on is therefore 2.20.3.1. In web-server access telemetry, requests to the Gridbox blog view whose author value is not a plain number are the signal, and by inference from the time-based technique, ones that take several seconds to answer are the likelier successful probes. A numeric author filter is normal browsing.

vulnerability26 Jul 14:08Zmulti-sourceOpen finding →
Sources: mySites.guru · Balbooa

2026-08-28 · view entry permalink →

HIGHCVE-2026-74253 +1exploitedNATOB2

Sourcerer for Joomla: unauthenticated RCE exploited in the wild since before a working fix existed; the vendor's first two patches did not close it, and the CVE was re-scoped in place to widen the affected range

CVE-2026-74253 (Regular Labs' Sourcerer, the Joomla extension that renders PHP, JS and CSS embedded in content) is CWE-94 (Improper Control of Generation of Code), CVSS 4.0 10.0 (AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H, every metric at its worst), credited to finder Lukasz Rybak. Before Sourcerer 14.0.0, only article-text content had its origin verified before Sourcerer would execute embedded code; code reaching the page through a module, component, page head, or any other rendering position ran unconditionally. 14.0.0 (17 Aug) added trust-marking for article content and unmodified custom-module output, but did not close every route by which untrusted content could reach the render (URL and form parameters, raw request bodies, uploads, cookies and headers all remained live) and the CVE record originally scoped the fix as "<14.0.0", affected 1.0.0–13.1.1.

The flaw has been under active exploitation since roughly 2026-08-19 per the Joomla Security Strike Team: "Exploited Yes, in the wild since roughly 19 August 2026 per the Joomla Security Strike Team, confirmed to us 24 August 2026" (mySites.guru, citing the Joomla Security Strike Team, 2026-08-26), two days after the first "fix" shipped and seven days before a working one existed. Sourcerer 15.0.0, also never tagged a security release, also failed to close it. Only 16.0.0 (26 Aug) closes the untrusted-input-delivery routes and additionally blocks common filesystem-write PHP functions by default. On 2026-08-26 the Joomla CNA re-scoped CVE-2026-74253 in place, widening the affected range from 1.0.0–13.1.1 to 1.0.0–15.0.0: "the Joomla CNA widened CVE-2026-74253 from 'Sourcerer < 14.0.0' to 'Sourcerer < 16.0.0', moving the affected range from 1.0.0-13.1.1 to 1.0.0-15.0.0, after the vendor's first two attempts at a fix turned out not to close the flaw" (mySites.guru, 2026-08-26), meaning every site that updated to 14.0.0, 14.0.1 or 15.0.0 in good faith, told by both its extension manager and the CVE record itself that it was patched, was exploitable the entire time.

HTML-escaping input is explicitly not a mitigation here, and the reason is design rather than oversight: "code written in a WYSIWYG editor arrives with its angle brackets converted to HTML entities. So that code still runs, Sourcerer decodes entities inside its own tags before handling the contents" (mySites.guru, 2026-08-26), the decoding cannot distinguish administrator-typed code from attacker-supplied text. PHP execution is enabled by default; the default forbidden-function list blocks shell-exec functions but not file-write functions. A separate, earlier CVE, CVE-2026-64796 (fixed in 13.0.0, affected 1.0.0–12.2.8), closed only the article-content path and does not protect against this one.

Triage: any site that "patched" Sourcerer to 14.x or 15.0.0 between 17 and 26 August must be re-verified against 16.0.0 and treated as having been exposed the entire window regardless of what its extension manager reported. Look for PHP execution originating from content-rendering code paths outside article bodies (module output, page-head injection, or request-parameter-derived content reaching Sourcerer's render function) since that is exactly the delivery route the 14.0.0/15.0.0 fixes failed to close. A web-server process spawning a shell or writing new PHP files to disk from within Joomla's content-rendering pipeline has no legitimate explanation.

The Joomla CNA widened CVE-2026-74253 from "Sourcerer < 14.0.0" to "Sourcerer < 16.0.0", moving the affected range from 1.0.0-13.1.1 to 1.0.0-15.0.0, after the vendor's first two attempts at a fix turned out not to close the flaw.

mySites.guru 2026-08-26

Exploited Yes, in the wild since roughly 19 August 2026 per the Joomla Security Strike Team, confirmed to us 24 August 2026.

mySites.guru, citing the Joomla Security Strike Team

Code written in a WYSIWYG editor arrives with its angle brackets converted to HTML entities. So that code still runs, Sourcerer decodes entities inside its own tags before handling the contents.

mySites.guru 2026-08-26
vulnerability28 Aug 05:35Zsingle-sourceOpen finding →
Sources: mySites.guru

2026-08-28 · view entry permalink →

NOTABLECVE-2026-67365NATOB2

iCagenda Calendar module for Joomla: unauthenticated SQL injection via com_ajax needs no session, token or account (CVE-2026-67365, CVSS 9.2), and the vulnerable module's own version number does not track the package version

The Joomla project's CNA published CVE-2026-67365 on 2026-08-14: an unauthenticated SQL injection (CWE-89) in mod_icagenda_calendar, the Calendar module bundled with the iCagenda events extension, reachable via com_ajax (Joomla's generic anonymous front-end AJAX entry point) with no session, token or account required. Rated CVSS 4.0 9.2 Critical (AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:L/VA:L/SC:H/SI:H/SA:H): "Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account" (Joomla CNA record, quoted by mySites.guru, 2026-08-17). Affected 4.0.0–4.0.11; fixed in 4.0.12. The flaw was reported by Joep van Antwerpen of Onvio, not mySites.guru's own find.

The operationally important detail is a version-tracking trap: the vulnerable Calendar module's own version number stayed pinned at 4.0.7 through package releases 4.0.8, 4.0.9, 4.0.10 and 4.0.11, and only advanced to 4.0.12 with the fix, "The Calendar module stayed at 4.0.7 through the 4.0.8, 4.0.9, 4.0.10 and 4.0.11 releases and only moved with 4.0.12, so the module version and the package version disagree and a site can look patched when it is not." (mySites.guru, 2026-08-17). A naive version check against the package number (in either direction) gives a wrong answer for this specific component. A second, independent detection trap sits upstream of that: at the time of mySites.guru's writing, iCagenda's own update feed had not yet been updated to list 4.0.12, even though the fixed release was already shipping and installing on real sites, "the feed still lists 4.0.11 from this date and nothing above it, even though 4.0.12 is shipping and installing on real sites. A site running an update check is told it is current" (mySites.guru, 2026-08-17), meaning an automated update-status check could report a vulnerable site as current independent of the module-version trap above. No vendor advisory or changelog entry exists for this fix beyond the CVE record itself at time of writing. This is the second security issue in iCagenda in two months and unrelated to the first: CVE-2026-48939, an unauthenticated file-upload flaw already CISA-KEV-listed, was fixed in 4.0.8/3.9.15 and does not cover this SQL injection.

Triage: hunt and inventory tooling should key on the Calendar module's own reported version, not the iCagenda package version, when assessing exposure to this specific CVE. On the wire, unauthenticated com_ajax requests targeting the iCagenda calendar component carrying SQL-metacharacter payloads in parameters are the delivery shape; iCagenda's legitimate calendar AJAX traffic carries only structured date/view parameters, so a request with SQL syntax in those fields has no benign explanation.

Joomla Extension - icagenda.com - Unauthenticated SQL injection in iCagenda < 4.0.0-4.0.11 - Unauthenticated SQL injection in mod_icagenda_calendar (iCagenda), reachable via com_ajax with no session, token or account.

Joomla CNA (CVE-2026-67365 record), quoted by mySites.guru

The Calendar module stayed at 4.0.7 through the 4.0.8, 4.0.9, 4.0.10 and 4.0.11 releases and only moved with 4.0.12, so the module version and the package version disagree and a site can look patched when it is not.

The feed still lists 4.0.11 from this date and nothing above it, even though 4.0.12 is shipping and installing on real sites. A site running an update check is told it is current.

mySites.guru 2026-08-17
vulnerability28 Aug 05:32Zsingle-sourceOpen finding →
Sources: mySites.guru

Earlier coverage (6)

2026-08-28HIGHNATOB2YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fixmySites.guru found three unauthenticated flaws in YOOtheme ZOO (com_zoo) for Joomla, affecting every version 1.0.0–4.1.63: CVE-2026-74803 (CVSS 10.0) is an arbitrary-file-upload-to-RCE via a Content-Type-only validation bypass in the front-end submission form; CVE-2026-74804 (CVSS 9.3) is a precondition-free unauthenticated SQL injection reachable even with no submission form configured. Fixed in ZOO 4.1.66 after two follow-up releases; no fix exists for the 3.x line.2026-08-02HIGHNATOB2CVE-2026-65766 and CVE-2026-65879, SP Page Builder for Joomla: a CSRF token Joomla hands to anonymous visitors is the only guard on an ORDER BY injection, plus a shipped-in-source shared secret that opens a mail relaymySites.guru disclosed four vulnerabilities in JoomShaper's SP Page Builder 6.7.0 on 2026-07-27, all fixed the same day in 6.7.1, with four CVEs assigned by the Joomla CNA and a fifth (CVE-2026-65876, 9.2, an unauthenticated SQL injection the discloser did not report or test) covering the same versions, so 6.7.1 fixes five issues, not four. CVE-2026-65766 (Joomla CNA, CVSS 4.0 9.2) places a request value straight into the ORDER BY clause of the Dynamic Content endpoint's query; the only control in front of it is a Joomla CSRF token, which Joomla issues to every anonymous visitor on page load, so a scripted attacker fetches a token and replays it, effectively pre-authentication SQL injection that reads the entire Joomla database, password hashes included. CVE-2026-65879 is a design flaw rather than a slip: the contact-form addons sign the configured recipient address with a secret hardcoded identically into every shipped copy of the extension, so anyone holding the extension can forge a signature and send mail to any recipient with a spoofed sender through the site's own mail server. The same extension's unauthenticated icon-upload zero-day was being exploited in the wild in June 2026.2026-08-01NOTABLENATOB2CVE-2026-65883, Aimy Captcha-Less Form Guard for Joomla: the anti-spam token is deserialized before any check, and the XOR keystream ships in the same page (CVSS 9.8)VulnCheck disclosed CVE-2026-65883 on 2026-07-30, an unauthenticated PHP object injection in the Aimy Captcha-Less Form Guard plugin for Joomla, versions 18.0 through 20.0 and fixed in 20.1. The plugin base64-decodes a hidden form token, runs it through a repeating-key XOR and passes the result straight to unserialize() with no signature and no allowed_classes, and because the plugin renders a ciphertext for that same keystream in every protected form, the key is recoverable and the object forgeable. On Joomla 3.9 through 5.2.1 it chains through a core gadget to remote code execution as the web user. No exploitation is reported, but three other unauthenticated Joomla extension flaws disclosed this year were exploited in the wild and KEV-listed.2026-07-11HIGHNATOB2Joomla file-upload RCE wave adds RSFiles! (CVE-2026-57827, unauth, CVSS 10.0) and Phoca Download (CVE-2026-57828, CVSS 9.0)Two more Joomla third-party extensions from the same researcher-driven disclosure wave patched arbitrary-file-upload-to-RCE flaws on 2026-07-10: RSFiles! (com_rsfiles) up to 1.17.11 lets any unauthenticated visitor upload and execute a .php file in its web-root downloads folder (CVE-2026-57827, CVSS 4.0 10.0, fixed 1.17.12), and Phoca Download (com_phocadownload) up to 6.1.2 lets a logged-in member bypass the file-type allow-list on its non-default member-upload feature (CVE-2026-57828, CVSS 4.0 9.0, fixed 6.1.3). No public PoC and no confirmed exploitation of these two yet, but earlier members of this exact CWE-434 wave reached CISA KEV within days; any Swiss/EU municipal or public-sector Joomla site running these extensions should update now and hunt for web shells.2026-07-10HIGHexploitedNATOB1CVE-2026-48939, iCagenda for Joomla: unauthenticated file-upload-to-RCE, exploited as a zero-day, added to CISA KEV (CVSS 4.0 10.0)CISA added CVE-2026-48939 to its Known Exploited Vulnerabilities catalog on 2026-07-10. The flaw in iCagenda, a widely deployed Joomla events/calendar extension, lets an unauthenticated visitor upload a PHP web shell through the public event-submission form; on Joomla 6 this yields remote code execution, and the underlying access-control bypass affects every Joomla version. It was exploited in the wild before a patch existed. Any Joomla site running iCagenda ≤ 4.0.7 (or ≤ 3.9.14 on the legacy branch) must update now and hunt for pre-patch compromise, relevant to the many Swiss and European municipal and public-sector sites built on Joomla.2026-07-09HIGHexploitedCVE-2026-56291, Balbooa Forms for Joomla: unauthenticated file-upload RCE exploited as a zero-day (CVSS 10.0)Balbooa Forms (the com_baforms Joomla component) up to and including 2.4.0 exposed its frontend attachment-upload handler to any anonymous visitor with no authentication, no CSRF token, and no file-extension allow-list, allowing a .php upload to be written into a web-served directory and executed, unauthenticated RCE (CWE-434). It was exploited as a zero-day before the 2.4.1 fix (9 July 2026) and attacks continue against unpatched sites. Anyone running Joomla with Balbooa Forms should update to 2.4.1 now and check for tampering.

Co-occurring entities

Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Where this entity is cited

  • Vulns9

Source distribution

  • mysites.guru14 (70%)
  • balbooa.com2 (10%)
  • cisa.gov2 (10%)
  • rsjoomla.com1 (5%)
  • vulncheck.com1 (5%)
All cited sources (20)