miniOrange OAuth Client flaw enables Joomla account takeover
A critical flaw in the miniOrange OAuth Client extension for Joomla allows unauthenticated account takeover, including access to administrator accounts.
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
A critical flaw in the miniOrange OAuth Client extension for Joomla allows unauthenticated account takeover, including access to administrator accounts.
mySites.guru says it found 19 vulnerabilities in 17 Joomla extensions during June and July 2026, including five rated CVSS 10.0.
Fabrikar has released Fabrik 4.7.2 for Joomla, addressing 16 CVE-listed vulnerabilities that include unauthenticated remote code execution, SQL injection and…
Multiple security issues in JEM, the Joomla Event Manager component, affect versions below 5.0.1, including stable 5.0.0. The most serious allows anonymous…
YOOtheme has fixed three unauthenticated vulnerabilities in its ZOO Joomla extension, including a critical file-upload flaw that can lead to remote code…
A critical, unauthenticated SQL injection affects the iCagenda Calendar module for Joomla, with administrators urged to update to version 4.0.12.
Regular Labs has released Sourcerer 14.0.0 to address a critical Joomla vulnerability that could execute PHP from unverified or reflected content.
mySites.guru says PHP 8.5.7 is behind on security patches even though it is newer than fully patched PHP 8.4.24.
Phoca Cart users should review their installed version after a published analysis identified a critical SQL injection in the Joomla extension’s public product…
JoomShaper has fixed two unauthenticated vulnerabilities in SP Page Builder for Joomla, including a critical flaw that could enable remote code execution…
Two medium-severity access control vulnerabilities in the Cotton Cloud file-storage extension for Joomla have been fixed in version 2.0.3, according to…
Fabrik for Joomla up to version 4.6.6 contains an unauthenticated remote code execution flaw in its calc element. Tracked as CVE-2026-66915, the issue has a…