
Fabrik 4.7.2 for Joomla: A Long List of Security Fixes
Fabrik 4.7.2 for Joomla closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Here is the full list and what to do.
Tips, tutorials, and updates about managing your WordPress and Joomla sites with mySites.guru.
Overdue Last read · last published · next check
Last read 4 days ago, longer than this feed's 9 hours schedule.

Fabrik 4.7.2 for Joomla closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Here is the full list and what to do.

mySites.guru found and reported multiple security issues in JEM (Joomla Event Manager), including an unauthenticated article overwrite. Five CVEs are assigned. There is no stable fix yet, so here is what to do.

Joomla 5.4.8 and 6.1.3 break four Template Manager actions with a Snooping out of bounds error. Creating component and plugin overrides, and creating and deleting template folders, all fail. Here is the cause, the manual fix, and how to reverse it.

YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus an unauthenticated SQL injection. All three are fixed in 4.1.64, and 4.1.65 followed within the hour. Install 4.1.65.

CVE-2026-67365 is an unauthenticated SQL injection in the iCagenda Calendar module for Joomla, scored 9.2 Critical. Fixed in 4.0.12.

Sourcerer, the Joomla extension, ran PHP from page content it could not trace to a verified source. CVE-2026-74253 scores 10.0 critical. Update to 14.0.0.

PHP 8.5.7 shows amber while 8.4.24 shows green because the badge checks whether you are on the newest patch in your branch, not which branch you picked.

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 sites running Phoca Cart 6.x are not offered it.

mySites.guru found a pre-authentication remote code execution flaw in SP Page Builder for Joomla, in the same 6.7.1 release that fixed our earlier reports. Update to 6.8.0 now.

Two access control flaws in Cotton Cloud for Joomla. The first fix closed the door and left the room unlocked. CVE-2026-67283 and CVE-2026-67284 are fixed in 2.0.3.

A new Joomla Manual page sets out 20 rules for how extension developers should handle a security report. Republished here in full under the JEDL.

Two CVSS 10.0 RCEs in the Fabrik Joomla extension. Its 4.7.0 fix was announced as stable, restricted to a test group, then relabelled a release candidate.