mySites.guru (Joomla/WordPress fleet security)
mysites-guru · B · active
Joomla/WordPress fleet-management vendor whose research team discovers and reproduces third-party-extension file-upload-to-RCE zero-days ahead of CVE assignment; original disclosing party for the mid-2026 Joomla extension file-upload RCE wave (SP Page Builder, Page Builder CK, Balbooa Forms) and for CVE-2026-48939 (iCagenda, CISA-KEV 2026-07-10). ADDED as candidate 2026-07-10 (2009Z run), cited as published primary for the iCagenda entry; fetch via jina (`python3 tools/fetch_source.py jina https://mysites.guru/blog/<slug>/`). Promote to active after 3 contributing runs. | 2026-07-11 contributed primary content again (RSFiles! CVE-2026-57827 + Phoca Download CVE-2026-57828, two more members of the Joomla-extension CWE-434 file-upload wave); consistent dated technically-precise disclosures, candidate still awaiting activation. | 2026-07-26 weekly quality audit: promoted candidate → active on the documented lifecycle bar (cited by published entries from 5 distinct runs; the bar is 3). The promotion had never been executed because nothing counted contributing runs — the digest now emits sources.promotion_due (tools/run_summary.py). | 2026-07-28: jina reader returned navigation chrome only. No demotion — transport/anti-bot block, not content death. | 2026-08-11: reader returns the extension-vulnerability post listing but with no per-item publication dates, so in-window status cannot be established for any item; S1 and S3 hit this independently. Recency-uncertain listings are excluded rather than included speculatively — a dated feed path for this publisher is the open recipe question. | 2026-08-24 (0902Z quality audit) ROOT-CAUSE FIX: fetch_method was pinned to `jina` with rss_url null while the reader key pool is fully exhausted, so the ORIGINAL disclosing party for the recurring Joomla third-party-extension RCE stream was effectively unfetchable. Three audits (2026-07-26, 08-02, 08-24) recovered a miss from this stream. `https://mysites.guru/rss.xml` returns HTTP 200 with dated items over direct transport (verified 2026-08-24). Do NOT re-pin to jina.
Cited in 13 entries
Citation cadence
Citation days per ISO week (4 weeks of coverage span, total 8).
- 2026-W31 vulnerability status roll-up — twelve CVEs stood at confirmed exploitation, three carry public exploit chains, and a dense critical tail hit management planes, OT, ERP and the AI toolchain2026-08-02
- Joomla third-party-extension wave status: the wave crossed from disclosed to evidenced this week — server access logs showing exploitation requests, and 92 planted administrator accounts on one live site2026-08-02
- Every authentication bypass disclosed this week came from code accepting an attacker-supplied value as proof of identity — the check ran, it just validated the wrong thing2026-08-02
- CVE-2026-65766 and CVE-2026-65879 — SP Page Builder for Joomla: a CSRF token Joomla hands to anonymous visitors is the only guard on an ORDER BY injection, plus a shipped-in-source shared secret that opens a mail relay2026-08-02
- CVE-2026-65884 / CVE-2026-65885 — Balbooa Gridbox for Joomla: anyone can register themselves straight into an administrator group, then upload PHP; 23 flaws found in a vendor-invited audit and exploitation is under way2026-07-31
- Joomla third-party-extension vulnerability wave status: the mySites.guru campaign added a new technique class this week — a client-supplied cookie accepted as proof of identity, giving anonymous Super User access2026-07-26
- CVE-2026-61425 — Balbooa Gridbox for Joomla: a client-supplied cookie is accepted as proof of identity, giving anonymous Super User access2026-07-26
- A researcher-driven Joomla extension file-upload wave produced four unauthenticated RCE disclosures this week — several exploited as zero-days before a patch existed2026-07-12
- Looking ahead — 2026-W282026-07-12
- Joomla file-upload RCE wave adds RSFiles! (CVE-2026-57827, unauth, CVSS 10.0) and Phoca Download (CVE-2026-57828, CVSS 9.0)2026-07-11
- CVE-2026-48939 — iCagenda for Joomla: unauthenticated file-upload-to-RCE, exploited as a zero-day, added to CISA KEV (CVSS 4.0 10.0)2026-07-10
- CVE-2026-56291 — Balbooa Forms for Joomla: unauthenticated file-upload RCE exploited as a zero-day (CVSS 10.0)2026-07-09
- CVE-2026-48908 / CVE-2026-56290 — two Joomla page-builder extensions hit CISA KEV the same day for unauth file-upload RCE zero-days2026-07-08