JoomlaForever.com!
  • Home
  • About US
  • News
  • Test & Reviews
  • Tutorials
  • Tips & Tricks
  • Contact US
  • Login

News - Security News

JoomlaForever.com! No image is available

Critical iCagenda File Upload RCE: Patch CVE-2026-48939 Now

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 18 July 2026

CVE-2026-48939 is a critical iCagenda file-upload vulnerability that can result in PHP code execution on affected Joomla sites. Administrators should upgrade the extension immediately, then investigate for signs of unauthorised uploads or execution because the flaw is listed in CISA’s Known Exploited Vulnerabilities catalog.

Read more: Critical iCagenda File Upload RCE: Patch CVE-2026-48939 Now

JoomlaForever.com! No image is available

Joomla Offered Update Has Expired: Meaning and Safe Next Steps

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 18 July 2026

The Joomla message “Offered update has expired” can interrupt a routine core update, but the available evidence indicates that it is an update-state, metadata, or timing condition—not a separately tracked security vulnerability. This guide explains how to respond calmly, protect the site before retrying, and decide when to seek confirmation through official Joomla channels.

Read more: Joomla Offered Update Has Expired: Meaning and Safe Next Steps

JoomlaForever.com! No image is available

How to Detect and Clean the JCE Profiles Hack on Joomla Sites

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 18 July 2026

The JCE profiles hack refers to CVE-2026-48907, an actively exploited Joomla extension vulnerability that can let unauthenticated attackers create editor profiles and ultimately upload and execute PHP code. Joomla administrators should update affected JCE installations, assess sites for unauthorised profiles and suspicious uploads, and treat patching as only the first stage of remediation.

Read more: How to Detect and Clean the JCE Profiles Hack on Joomla Sites

JoomlaForever.com! No image is available

Quix Page Builder SQL Injection: Update to 6.2.1 Now

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 18 July 2026

Quix Page Builder Pro versions 1.0 through 6.2.0 are affected by CVE-2026-58078, an unauthenticated SQL injection vulnerability. Joomla administrators should update to Quix 6.2.1 or later, assess potentially exposed data, and check their wider extension inventory for related SQL injection risks.

Read more: Quix Page Builder SQL Injection: Update to 6.2.1 Now

Page 3 of 6

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6

About us

JF Logo

JoomlaForever.com is an independent source publishing news and tests about Joomla CMS.

Contact info

  • JoomlaForever.com!
  • Contact owner:  Bjørn Ove Bremnes
  • General info:
Social Medial:
  • JoomlaForever on Facebook
  • JoomlaForever on Twitter / X

Useful links

  • Home
  • About JoomlaForever.com
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
  • Comments Policy
  • Sitemap
  • Register account
  • Login
This site is sponsored by:
Bredc.com logo

All our content is original, and therefore it's copyrighted by JoomlaForever.com!

If you wish to use our content on another site, you will need explicit allowance from JoomlaForever.com! You can do this by emailing  or by using our form (see "Useful links")!

ALL RIGHTS © 2019 - 2026.
JoomlaForever.com!, and this site is not affiliated with or endorsed by The Joomla! Project™. Any products and services provided through this site are not supported or warrantied by The Joomla! Project or Open Source Matters, Inc. Use of the Joomla!® name, symbol, logo and related trademarks is permitted under a limited license granted by Open Source Matters, Inc...