#Joomla
All CosmicBytez Labs articles tagged #Joomla, across news, security advisories, how-to guides, and projects.
- Security
CVE-2026-62415: Joomla Membership Pro Allows Unauthenticated File Upload
The Joomla extension Membership Pro prior to version 4.6.2 allowed unauthenticated users to upload media assets by default, exposing sites to potential...
- News
CISA Warns of Actively Exploited RCE Flaws in Joomla Extensions
CISA has added two Joomla extension vulnerabilities to its KEV catalog after attackers began exploiting arbitrary file upload flaws in iCagenda and...
- News
iCagenda and Balbooa Forms Joomla Flaws Exploited as Zero-Days
CISA has added two maximum-severity flaws in iCagenda and Balbooa Forms Joomla extensions to its KEV catalog following confirmed zero-day exploitation in...
- Security
CVE-2026-48939: iCagenda Unrestricted File Upload Allows PHP Code Execution
A critical unrestricted file upload vulnerability in the iCagenda Joomla event calendar plugin allows unauthenticated attackers to upload arbitrary PHP...
- Security
CVE-2026-56291: Balbooa Forms Unrestricted File Upload Enables Full RCE
A critical unauthenticated file upload vulnerability in Balbooa Forms for Joomla allows attackers to upload executable files and achieve full remote code...
- Security
CVE-2026-48908: JoomShaper SP Page Builder Unrestricted File Upload RCE
A critical unrestricted file upload vulnerability in JoomShaper's SP Page Builder allows unauthenticated attackers to upload arbitrary PHP files and...
- Security
CVE-2026-56290: Joomlack Page Builder Unauthenticated File Upload RCE — CISA KEV
A CVSS 10.0 unauthenticated arbitrary file upload vulnerability in the Joomlack Page Builder CK Joomla extension allows any remote attacker to upload a...
- Security
CVE-2026-49048: Critical SQL Injection in JoomCCK Joomla Extension
A critical unauthenticated SQL injection vulnerability (CVSS 9.8) in the JoomCCK Joomla extension allows attackers to read, modify, or delete database...
- News
CISA Orders Feds to Patch Max Severity Joomla Plugin Flaw by Friday
CISA has issued an emergency directive ordering federal agencies to patch CVE-2026-48907, a maximum-severity improper access control flaw in the Widget...
- News
CISA Warns of Actively Exploited Joomla JCE Flaw Allowing PHP Code Execution
CISA has added a maximum-severity vulnerability in the Joomla Content Editor (JCE) plugin to its Known Exploited Vulnerabilities catalog, warning that the...
- Security
CVE-2026-48907: Joomla Content Editor Unauthenticated PHP Upload Flaw
A maximum-severity improper access control flaw in Widget Factory's Joomla Content Editor allows unauthenticated attackers to upload and execute arbitrary...