News - Security News
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Two confirmed Joomla extension vulnerabilities require prompt action: CVE-2026-57833 affects AcyMailing and CVE-2026-58077 affects EDocman. Administrators should identify affected installations, update AcyMailing to 10.11.1 or later and EDocman to 3.9.0 or later, then assess whether publicly exposed sites may have disclosed database data.
Read more: Patch AcyMailing and EDocman for Two Joomla SQL Injection CVEs
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Joomla sites running affected DPCalendar releases should be updated promptly to address CVE-2026-57831, an unauthenticated blind SQL injection vulnerability that can expose database information. This advisory explains the confirmed affected versions, the correct upgrade targets, and the defensive checks site owners should complete after patching.
Read more: Patch DPCalendar Now: CVE-2026-57831 SQL Injection Guidance
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Joomla sites using JoomShaper’s SP Page Builder need an urgent version review after CVE-2026-48908, an actively exploited unauthenticated remote-code-execution vulnerability affecting versions before 6.6.2. The immediate priority is to update to version 6.6.2 or later; Joomla 3 operators who cannot do so should remove or disable the extension, investigate possible exposure and prepare a supported migration path.
Read more: JoomShaper Joomla 3 Support Freeze: CVE-2026-48908 and Required Actions
- Details
- Written by: Bjørn Ove Bremnes
- Parent Category: News
- Category: News - Security News
Joomla sites using AcyMailing 6.0.0 through 10.11.0 should update the extension to version 10.11.1 or later to remediate CVE-2026-56292, an unauthenticated SQL injection vulnerability. This advisory explains the confirmed Joomla scope, the official CVSS 4.0 rating, practical update steps, and the separate WordPress-only AcyMailing issue that agencies may also need to track.
Read more: AcyMailing Joomla SQL Injection: Update to 10.11.1 or Later