EasyStore 2.0.2 fixes three Joomla security flaws
JoomShaper’s EasyStore ecommerce extension for Joomla contained three serious vulnerabilities before version 2.0.2, including flaws that could expose customer…
News, security and craft for the Joomla ecosystem
Security releases, vulnerabilities and hardening for Joomla.
JoomShaper’s EasyStore ecommerce extension for Joomla contained three serious vulnerabilities before version 2.0.2, including flaws that could expose customer…
Regular Labs has released security fixes across roughly 30 Joomla extensions, addressing issues including SSRF, command injection and stored XSS…
Regular Labs has released security updates for roughly 30 Joomla extensions, addressing issues including SSRF, stored XSS and command injection. No CVEs were…
Joomlack has released PageBuilder CK 3.6.3 after researchers found that versions 3.6.0 through 3.6.2 only partially fixed a critical file-upload vulnerability…
A security flaw in the Joomla Events Booking extension allowed unauthenticated visitors to download other registrants’ invoices, exposing personal and payment…
mySites.guru has warned that Joomla administrators may overestimate the protection provided by hardened .htaccess files, since many extension vulnerabilities…
JoomDonation has released Membership Pro 4.6.2 to address a critical unauthenticated file upload vulnerability affecting versions through 4.6.1.
Two unauthenticated vulnerabilities in JoomDonation’s Events Booking Joomla extension allowed anonymous file uploads and exposed users’ names and email…
mySites.guru has reported a high-severity file-upload vulnerability in the Joomla extension DJ-Classifieds, which was being probed in the wild before the…
jDownloads has fixed a high-severity unauthenticated file-upload vulnerability affecting versions 4.1.0 through 4.1.5. Administrators should update to 4.1.6.
Two Joomla extensions have received security fixes for high-severity, unauthenticated vulnerabilities: SQL injection in JoomCCK and stored cross-site scripting…
mySites.guru has disclosed an unauthenticated, error-based SQL injection in ThemeXpert’s Quix Page Builder for Joomla, tracked as CVE-2026-58078 and rated High…