Joomla
Coverage of Joomla in the Nexus archive.
- Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites
CISA added two critical Joomla extension vulnerabilities (iCagenda and Balbooa Forms) to its KEV catalog, both rated with a CVSS score of 10. Attackers exploited these flaws to upload malicious PHP code, enabling remote server control. Patches are available, but exploitation continues on unpatched sites.
- CISA warns of actively exploited RCE flaws in Joomla extensions
CISA is warning about actively exploited remote code execution (RCE) vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla. Attackers are leveraging these flaws to achieve RCE through arbitrary file uploads.
- iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
CISA added two maximum-severity vulnerabilities in iCagenda and Balbooa Joomla extensions to its KEV catalog, citing reports of zero-day exploitation. Both flaws, rated 10.0 on the CVSS scale, are being actively exploited.
- CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV
CISA added four actively exploited vulnerabilities to its KEV catalog, including a critical path traversal flaw in Adobe ColdFusion (CVE-2026-48282) that could enable arbitrary code execution. The other flaws affect Joomla and Langflow, with all vulnerabilities being actively exploited.
- Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
Unknown threat actors compromised the update system for the Smart Slider 3 Pro plugin for WordPress and Joomla, distributing a backdoored version (3.5.1.35) via hijacked Nextend Servers. Patchstack, a WordPress security company, reported the incident, which affects a plugin with over 800,000 active installations.
- Smart Slider updates hijacked to push malicious WordPress, Joomla versions
Hackers hijacked the update system for the Smart Slider 3 Pro plugin, distributing malicious versions of WordPress and Joomla with multiple backdoors. The attack compromised the update process, allowing unauthorized access and potential data breaches.