mySites.guru (Joomla/WordPress fleet security)
mysites-guru · B · active
Joomla/WordPress fleet-management vendor whose research team discovers and reproduces third-party-extension file-upload-to-RCE zero-days ahead of CVE assignment; original disclosing party for the mid-2026 Joomla extension file-upload RCE wave (SP Page Builder, Page Builder CK, Balbooa Forms) and for CVE-2026-48939 (iCagenda, CISA-KEV 2026-07-10). ADDED as candidate 2026-07-10 (2009Z run), cited as published primary for the iCagenda entry; fetch via jina (`python3 tools/fetch_source.py jina https://mysites.guru/blog/<slug>/`). Promote to active after 3 contributing runs. | 2026-07-11 contributed primary content again (RSFiles! CVE-2026-57827 + Phoca Download CVE-2026-57828, two more members of the Joomla-extension CWE-434 file-upload wave); consistent dated technically-precise disclosures, candidate still awaiting activation. | 2026-07-26 weekly quality audit: promoted candidate → active on the documented lifecycle bar (cited by published entries from 5 distinct runs; the bar is 3). The promotion had never been executed because nothing counted contributing runs, the digest now emits sources.promotion_due (tools/run_summary.py). | 2026-07-28: jina reader returned navigation chrome only. No demotion, transport/anti-bot block, not content death. | 2026-08-11: reader returns the extension-vulnerability post listing but with no per-item publication dates, so in-window status cannot be established for any item; S1 and S3 hit this independently. Recency-uncertain listings are excluded rather than included speculatively; a dated feed path for this publisher is the open recipe question. | 2026-08-24 (0902Z quality audit) ROOT-CAUSE FIX: fetch_method was pinned to `jina` with rss_url null while the reader key pool is fully exhausted, so the ORIGINAL disclosing party for the recurring Joomla third-party-extension RCE stream was effectively unfetchable. Three audits (2026-07-26, 08-02, 08-24) recovered a miss from this stream. `https://mysites.guru/rss.xml` returns HTTP 200 with dated items over direct transport (verified 2026-08-24). Do NOT re-pin to jina.
Cited in 10 entries
Citation cadence
Citation days per ISO week (8 weeks of coverage span, total 7).
- YOOtheme ZOO for Joomla: unauthenticated file-upload RCE (CVSS 10.0) plus a precondition-free SQL injection reachable with no submission form at all, three releases in three days, and the 3.x line has no fix2026-08-28
- Sourcerer for Joomla: unauthenticated RCE exploited in the wild since before a working fix existed; the vendor's first two patches did not close it, and the CVE was re-scoped in place to widen the affected range2026-08-28
- miniOrange's SAML2Core library ships the same openssl_verify() tri-state authentication bypass across both its WordPress and Joomla SAML SSO products, one vendor code defect, two ecosystems, exploitation already attempted against the WordPress line2026-08-28
- iCagenda Calendar module for Joomla: unauthenticated SQL injection via com_ajax needs no session, token or account (CVE-2026-67365, CVSS 9.2), and the vulnerable module's own version number does not track the package version2026-08-28
- CVE-2026-65766 and CVE-2026-65879, SP Page Builder for Joomla: a CSRF token Joomla hands to anonymous visitors is the only guard on an ORDER BY injection, plus a shipped-in-source shared secret that opens a mail relay2026-08-02
- CVE-2026-61425, Balbooa Gridbox for Joomla: a client-supplied cookie is accepted as proof of identity, giving anonymous Super User access2026-07-26
- Joomla file-upload RCE wave adds RSFiles! (CVE-2026-57827, unauth, CVSS 10.0) and Phoca Download (CVE-2026-57828, CVSS 9.0)2026-07-11
- CVE-2026-48939, iCagenda for Joomla: unauthenticated file-upload-to-RCE, exploited as a zero-day, added to CISA KEV (CVSS 4.0 10.0)2026-07-10
- CVE-2026-56291, Balbooa Forms for Joomla: unauthenticated file-upload RCE exploited as a zero-day (CVSS 10.0)2026-07-09
- CVE-2026-48908 / CVE-2026-56290, two Joomla page-builder extensions hit CISA KEV the same day for unauth file-upload RCE zero-days2026-07-08