Joomla CMS
A popular content management system (CMS) whose extensions iCagenda and Balbooa Forms were exploited as zero-days.
A popular content management system (CMS) whose extensions iCagenda and Balbooa Forms were exploited as zero-days.
A Joomla extension for content editing, targeted in a global CMS exploitation campaign for web shell deployment.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added two maximum-severity vulnerabilities affecting iCagenda and Balbooa Forms extensions for Joomla to…
Developer of the iCagenda extension for Joomla that released patches for CVE-2026-48939 in versions 4.0.8 and 3.9.15.
A Joomla extension for event calendar management, affected by CVE-2026-48939 allowing arbitrary file upload and remote code execution.
A Joomla extension for form building, affected by CVE-2026-56291 allowing unauthenticated remote code execution.
A cybercrime crew left its server exposed for three weeks, revealing the inner workings of a mass site-hacking operation tracked as WP-SHELLSTORM.…
A cybercrime operation that breaks into websites at scale, plants webshell backdoors, and packages access for resale. Targeted WordPress and Joomla sites…
A Joomla editor with a maximum-severity vulnerability (CVE-2026-48907) added to CISA's exploited list. Fixed in version 2.9.99.5.
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence…