CyberSecurityBoardThreat Intel · CVEs · Products

Tag: Joomla

Cyber Products

Joomla CMS

A popular content management system (CMS) whose extensions iCagenda and Balbooa Forms were exploited as zero-days.

CMS content management system Joomla
July 13, 2026
Cyber Products

Joomla JCE Extension

A Joomla extension for content editing, targeted in a global CMS exploitation campaign for web shell deployment.

extension Joomla Joomla JCE vulnerability
July 13, 2026
Cyber Companies

JoomliC

Developer of the iCagenda extension for Joomla that released patches for CVE-2026-48939 in versions 4.0.8 and 3.9.15.

iCagenda Joomla JoomliC patch
July 13, 2026
Cyber Products

iCagenda Joomla Extension

A Joomla extension for event calendar management, affected by CVE-2026-48939 allowing arbitrary file upload and remote code execution.

calendar extension iCagenda Joomla
July 13, 2026
Cyber Products

Balbooa Forms Joomla Extension

A Joomla extension for form building, affected by CVE-2026-56291 allowing unauthenticated remote code execution.

Balbooa Forms extension Forms Joomla
July 13, 2026
Cyber Products

JCE Editor for Joomla

A Joomla editor with a maximum-severity vulnerability (CVE-2026-48907) added to CISA's exploited list. Fixed in version 2.9.99.5.

CVE-2026-48907 editor JCE editor Joomla
July 10, 2026