News
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Joomla sites running affected DPCalendar releases should be updated promptly to address CVE-2026-57831, an unauthenticated blind SQL injection vulnerability that can expose database information. This advisory explains the confirmed affected versions, the correct upgrade targets, and the defensive checks site owners should complete after patching.
Read more: Patch DPCalendar Now: CVE-2026-57831 SQL Injection Guidance
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Joomla sites using JoomShaper’s SP Page Builder need an urgent version review after CVE-2026-48908, an actively exploited unauthenticated remote-code-execution vulnerability affecting versions before 6.6.2. The immediate priority is to update to version 6.6.2 or later; Joomla 3 operators who cannot do so should remove or disable the extension, investigate possible exposure and prepare a supported migration path.
Read more: JoomShaper Joomla 3 Support Freeze: CVE-2026-48908 and Required Actions
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Joomla sites using AcyMailing 6.0.0 through 10.11.0 should update the extension to version 10.11.1 or later to remediate CVE-2026-56292, an unauthenticated SQL injection vulnerability. This advisory explains the confirmed Joomla scope, the official CVSS 4.0 rating, practical update steps, and the separate WordPress-only AcyMailing issue that agencies may also need to track.
Read more: AcyMailing Joomla SQL Injection: Update to 10.11.1 or Later
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Joomla sites using the Joomla Content Editor (JCE) extension should urgently check their installed version and update if it is earlier than 2.9.99.5. CVE-2026-48907 is a critical, actively exploited improper access control flaw that can permit unauthenticated remote code execution through the creation of editor profiles and PHP upload and execution.
Read more: Patch JCE Now for Actively Exploited CVE-2026-48907