Live This site runs Joomla 6.1.2
JoomClub

News, security and craft for the Joomla ecosystem

Security

Fabrik 4.7.2 fixes 16 Joomla vulnerabilities

Fabrikar has released Fabrik 4.7.2 for Joomla, addressing 16 CVE-listed vulnerabilities that include unauthenticated remote code execution, SQL injection and arbitrary file upload.

Research published by mySites.guru says every Fabrik release below 4.7.2 should be treated as affected. The Joomla CNA published records for all 16 issues; 15 credit mySites.guru as the finder. Four carry the maximum CVSS score of 10.0, while seven are rated Critical overall. The disclosure does not report confirmed exploitation.

The affected extension is Fabrik for Joomla, from Fabrikar. The issues include path traversal, directory listing, access-control failures, row and comment disclosure or manipulation, and a heredoc breakout. The CVEs are:

  • CVE-2026-76571, CVE-2026-76596, CVE-2026-76597, CVE-2026-76598, CVE-2026-76600, CVE-2026-76601, CVE-2026-76602, CVE-2026-76603, CVE-2026-76604, CVE-2026-76605, CVE-2026-76606, CVE-2026-76607, CVE-2026-76608, CVE-2026-76609, CVE-2026-77027 and CVE-2026-77992.

Administrators should download the newest 4.7.2 package directly from fabrikar.com and reinstall it even when the site already shows that version, because the release was reissued under the same version number. Joomla 3 sites cannot install Fabrik 4; there is no patched Fabrik 3 release. Check logs and files for signs of compromise after updating.

Originally reported by mySites.guru.