Gridbox 2.20.4.0 fixes Joomla security flaws
Balbooa has released Gridbox 2.20.4.0 for Joomla, fixing a high-severity CSRF vulnerability in language installation and a separate image path validation…
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
Balbooa has released Gridbox 2.20.4.0 for Joomla, fixing a high-severity CSRF vulnerability in language installation and a separate image path validation…
JCH Optimize versions before 9.4.0 are affected by six high-rated security issues, including XSS and an unauthenticated page-cache endpoint; administrators…
Two OrdaSoft Joomla extensions contain unauthenticated vulnerabilities: an SQL injection in Simple Membership and an access-control flaw in Touch Slider.
Joomla extension Event Gallery 6.6.0 addresses three security issues, including two medium-severity vulnerabilities affecting older releases and a low-severity…
A high-severity IDOR in Phoca Cart allowed unauthenticated visitors to download digital products purchased by other customers, according to mySites.guru.
ThemeXpert’s Quix Page Builder 6.3.4 addresses multiple security problems that could let guests access restricted content, editors execute server-side code and…
Joomla administrators running AcyMailing below 11.1.0 may not be warned about two security fixes because the extension’s update site can disappear from…
OrdaSoft has fixed a critical, unauthenticated PHP upload vulnerability and a separate SQL injection in OS CCK for Joomla, but affected sites must install the…
JoomCode has fixed a critical, unauthenticated SQL injection in its JCTables extension for Joomla. The flaw, tracked as CVE-2026-76570, affects every version…
Three OrdaSoft Joomla extensions contain unauthenticated SQL injection and reflected XSS vulnerabilities, with six CVEs assigned in total.
Joomla’s UP content plugin has fixed four vulnerabilities that could expose site files, enable code execution and permit database access.
Event Gallery 6.5.0 fixes eight security issues in the Joomla extension, including upload CSRF, reflected XSS and guessable cart and order identifiers.