RSS Amplifier

Blog

mySites.guru Blog

Tips, tutorials, and updates about managing your WordPress and Joomla sites with mySites.guru.

mysites.guruSource feed ↗12 posts

Overdue Last read · last published · next check
Last read 4 days ago, longer than this feed's 9 hours schedule.

Written by

Latest posts

Fabrik 4.7.2 for Joomla: A Long List of Security Fixes

Fabrik 4.7.2 for Joomla closes a long list of unauthenticated vulnerabilities, most of them found and reported by mySites.guru. Here is the full list and what to do.

Five Security Issues in JEM (Joomla Event Manager), and No Stable Fix Yet

mySites.guru found and reported multiple security issues in JEM (Joomla Event Manager), including an unauthenticated article overwrite. Five CVEs are assigned. There is no stable fix yet, so here is what to do.

Joomla 5.4.8 and 6.1.3 Break the Template Manager

Joomla 5.4.8 and 6.1.3 break four Template Manager actions with a Snooping out of bounds error. Creating component and plugin overrides, and creating and deleting template folders, all fail. Here is the cause, the manual fix, and how to reverse it.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.65

YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus an unauthenticated SQL injection. All three are fixed in 4.1.64, and 4.1.65 followed within the hour. Install 4.1.65.

iCagenda 4.0.12 fixes an unauthenticated SQL injection

CVE-2026-67365 is an unauthenticated SQL injection in the iCagenda Calendar module for Joomla, scored 9.2 Critical. Fixed in 4.0.12.

Sourcerer 14.0.0 fixes PHP execution from unverified content

Sourcerer, the Joomla extension, ran PHP from page content it could not trace to a verified source. CVE-2026-74253 scores 10.0 critical. Update to 14.0.0.

Why PHP 8.5.7 Shows Amber When PHP 8.4.24 Shows Green

PHP 8.5.7 shows amber while 8.4.24 shows green because the badge checks whether you are on the newest patch in your branch, not which branch you picked.

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 fix a front-end SQL injection

Phoca Cart 5.2.4, 6.1.7 and 4.0.13 patch an unauthenticated SQL injection in the Joomla extension's product filter. Joomla 5 sites running Phoca Cart 6.x are not offered it.

Unauthenticated Remote Code Execution in SP Page Builder found by mySites.guru

mySites.guru found a pre-authentication remote code execution flaw in SP Page Builder for Joomla, in the same 6.7.1 release that fixed our earlier reports. Update to 6.8.0 now.

Cotton Cloud Patched the Login, Then the Data

Two access control flaws in Cotton Cloud for Joomla. The first fix closed the door and left the room unlocked. CVE-2026-67283 and CVE-2026-67284 are fixed in 2.0.3.

Twenty Rules for Joomla Extension Developers Handling a Security Report

A new Joomla Manual page sets out 20 rules for how extension developers should handle a security report. Republished here in full under the JEDL.

The Fabrik Fiasco: Announced, Restricted, Relabelled

Two CVSS 10.0 RCEs in the Fabrik Joomla extension. Its 4.7.0 fix was announced as stable, restricted to a test group, then relabelled a release candidate.