Security
mySites.guru reports 19 Joomla extension vulnerabilities
mySites.guru says it found 19 vulnerabilities in 17 Joomla extensions during June and July 2026, including five rated CVSS 10.0.
The research identifies security problems in several widely used Joomla products. The named issues include an authentication bypass in Gridbox, customer invoice exposure and forged-order attacks in EasyStore, and multiple vulnerabilities in SP Page Builder, including pre-authentication SQL injection, an open mail relay and unauthenticated remote code execution.
Phoca Cart: front-end SQL injectionJEM: five reported issues, with no stable fix available when the article was published
mySites.guru says it privately notified each vendor before disclosure. The article does not provide CVE identifiers or affected and fixed version numbers for the issues listed here, and it does not report whether the vulnerabilities are being actively exploited. Administrators should check the relevant vendors’ security notices, update affected extensions when fixes are available, and review exposure where no stable patch has been released.
Originally reported by mySites.guru.