JoomlaForever.com!
  • Home
  • About US
  • News
  • Test & Reviews
  • Tutorials
  • Tips & Tricks
  • Contact US
  • Login

News

JoomlaForever.com! No image is available

Patch DPCalendar Now: CVE-2026-57831 SQL Injection Guidance

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 18 July 2026

Joomla sites running affected DPCalendar releases should be updated promptly to address CVE-2026-57831, an unauthenticated blind SQL injection vulnerability that can expose database information. This advisory explains the confirmed affected versions, the correct upgrade targets, and the defensive checks site owners should complete after patching.

Read more: Patch DPCalendar Now: CVE-2026-57831 SQL Injection Guidance

JoomlaForever.com! No image is available

JoomShaper Joomla 3 Support Freeze: CVE-2026-48908 and Required Actions

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 17 July 2026

Joomla sites using JoomShaper’s SP Page Builder need an urgent version review after CVE-2026-48908, an actively exploited unauthenticated remote-code-execution vulnerability affecting versions before 6.6.2. The immediate priority is to update to version 6.6.2 or later; Joomla 3 operators who cannot do so should remove or disable the extension, investigate possible exposure and prepare a supported migration path.

Read more: JoomShaper Joomla 3 Support Freeze: CVE-2026-48908 and Required Actions

JoomlaForever.com! No image is available

AcyMailing Joomla SQL Injection: Update to 10.11.1 or Later

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 17 July 2026

Joomla sites using AcyMailing 6.0.0 through 10.11.0 should update the extension to version 10.11.1 or later to remediate CVE-2026-56292, an unauthenticated SQL injection vulnerability. This advisory explains the confirmed Joomla scope, the official CVSS 4.0 rating, practical update steps, and the separate WordPress-only AcyMailing issue that agencies may also need to track.

Read more: AcyMailing Joomla SQL Injection: Update to 10.11.1 or Later

JoomlaForever.com! No image is available

Patch JCE Now for Actively Exploited CVE-2026-48907

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 17 July 2026

Joomla sites using the Joomla Content Editor (JCE) extension should urgently check their installed version and update if it is earlier than 2.9.99.5. CVE-2026-48907 is a critical, actively exploited improper access control flaw that can permit unauthenticated remote code execution through the creation of editor profiles and PHP upload and execution.

Read more: Patch JCE Now for Actively Exploited CVE-2026-48907

Subcategories

News - Security News

News - General Articles

Page 4 of 7

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7

About us

JF Logo

JoomlaForever.com is an independent source publishing news and tests about Joomla CMS.

Contact info

  • JoomlaForever.com!
  • Contact owner:  Bjørn Ove Bremnes
  • General info:
Social Medial:
  • JoomlaForever on Facebook
  • JoomlaForever on Twitter / X

Useful links

  • Home
  • About JoomlaForever.com
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
  • Comments Policy
  • Sitemap
  • Register account
  • Login
This site is sponsored by:
Bredc.com logo

All our content is original, and therefore it's copyrighted by JoomlaForever.com!

If you wish to use our content on another site, you will need explicit allowance from JoomlaForever.com! You can do this by emailing  or by using our form (see "Useful links")!

ALL RIGHTS © 2019 - .
JoomlaForever.com!, and this site is not affiliated with or endorsed by The Joomla! Project™. Any products and services provided through this site are not supported or warrantied by The Joomla! Project or Open Source Matters, Inc. Use of the Joomla!® name, symbol, logo and related trademarks is permitted under a limited license granted by Open Source Matters, Inc...