Joomla extensions hit by SQL injection and stored XSS flaws
Two Joomla extensions have received security fixes for high-severity, unauthenticated vulnerabilities: SQL injection in JoomCCK and stored cross-site scripting…
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
Two Joomla extensions have received security fixes for high-severity, unauthenticated vulnerabilities: SQL injection in JoomCCK and stored cross-site scripting…
mySites.guru has disclosed an unauthenticated, error-based SQL injection in ThemeXpert’s Quix Page Builder for Joomla, tracked as CVE-2026-58078 and rated High…
JoomShaper has released Joomla 3 security updates for Helix Ultimate, Helix3 and SP Page Builder, reversing its recent decision to stop providing patches for…
Digital Peak has reported a serious vulnerability in its DPCalendar event-calendar component that can enable unauthorised access to data stored in a Joomla…
mySites.guru has disclosed an unauthenticated SQL injection in the Joomla extension EDocman, allowing database contents to be read remotely. JoomDonation fixed…
Digital Peak has fixed a high-severity, unauthenticated SQL injection in its DPCalendar extension for Joomla, which could expose the site database to anonymous…
Phoca Download for Joomla contained an authenticated remote code execution flaw in versions up to 6.1.2, allowing eligible members to upload and run PHP files…
RSJoomla has fixed a critical security flaw in RSFiles! for Joomla that could let unauthenticated visitors upload and execute PHP code on affected websites.
AcyMailing versions 6.0.0 through 10.11.0 contain an unauthenticated SQL injection affecting Joomla and WordPress installations. Administrators should update…
Joomla administrators using com_baforms should update to version 2.4.3 or later after two unauthenticated remote code execution flaws were disclosed in Balbooa…
Joomla has released versions 6.1.2 and 5.4.7 with security fixes for the core and web services, alongside more than 35 bug fixes and stability improvements…
Joomla sites running 4.0.0-5.4.6 or 6.0.0-6.1.1 are affected by an Incorrect Access Control issue in com_fields; administrators should upgrade to 5.4.7 or…