Sourcerer 14.0.0 fixes critical Joomla code execution flaw
Regular Labs has released Sourcerer 14.0.0 to address a critical Joomla vulnerability that could execute PHP from unverified or reflected content.
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
Regular Labs has released Sourcerer 14.0.0 to address a critical Joomla vulnerability that could execute PHP from unverified or reflected content.
A critical, unauthenticated SQL injection affects the iCagenda Calendar module for Joomla, with administrators urged to update to version 4.0.12.
mySites.guru says PHP 8.5.7 is behind on security patches even though it is newer than fully patched PHP 8.4.24.
Phoca Cart users should review their installed version after a published analysis identified a critical SQL injection in the Joomla extension’s public product…
JoomShaper has fixed two unauthenticated vulnerabilities in SP Page Builder for Joomla, including a critical flaw that could enable remote code execution…
Two medium-severity access control vulnerabilities in the Cotton Cloud file-storage extension for Joomla have been fixed in version 2.0.3, according to…
Fabrik for Joomla up to version 4.6.6 contains an unauthenticated remote code execution flaw in its calc element. Tracked as CVE-2026-66915, the issue has a…
Balbooa’s Joomla page builder Gridbox contains 23 critical vulnerabilities, including pre-authentication remote code execution. mySites.guru says some flaws…
JCE 2.9.99.10 fixes a file-handling vulnerability that could let a privileged, authenticated user hide a file in the directory they were viewing.
JoomShaper has released SP Page Builder 6.7.1 to fix four vulnerabilities affecting version 6.7.0 and earlier, including a pre-authentication SQL injection and…
Joomla sites are facing continued automated scanning in 2026 for AJAX handlers that verify neither authentication nor permissions, leaving extensions and…
Joomla administrators can use a core-versus-third-party filter in the full extension list to identify non-core extensions installed on a site, an inventory…