Skip to main content

Joomla extension vulnerabilities that reach Joomla 3

The one-click core patch cannot touch your extensions, so they are a separate exposure. Each row below is a vulnerability rule in the mySites.guru database for a Joomla extension whose Joomla 3 branch is affected. 52 rules across 25 extensions, exported 2 Oct 2026.

Whether a flaw is fixable for Joomla 3 depends entirely on the vendor. Some still ship fixes for a Joomla 3 branch, some said they had stopped and kept shipping, and some never published a Joomla 3 fix at all.

52
rules that match a Joomla 3 branch
25
extensions affected
17
rated Critical
and 22 rated High
22.3%
of Joomla 3 sites run at least one extension with a known vulnerability

Rule counts are from the mySites.guru vulnerability database, exported 2 Oct 2026. The site figure is across sites connected to mySites.guru, 28 August 2026.

Why the vendor decides what you can fix

An extension flaw is closed by an update from the vendor, and an update only exists if the vendor still builds one for Joomla 3.

Several vendors still ship Joomla 3 security releases. Digital Peak put DPCalendar 8.x into hybrid maintenance in May 2024 and shipped 8.19.4, 8.19.5 and 8.19.6 for Joomla 3 in 2026. Tassos shipped Convert Forms 4.4.16 and 4.4.17 for Joomla 3 in July and August 2026. J2Store has patched its Joomla 3 line the same day as J2Store 4, until its end of life on 19 October 2026. YOOtheme removed Joomla 3 support in Pro 5.0, yet its 4.5.x line received all four of its 2026 security fixes in August.

Others said they had stopped, then kept shipping. JoomShaper announced on 9 July 2026 that Joomla 3 would get no security patches, shipped Joomla 3 security packages for Helix Ultimate, Helix3 and SP Page Builder six days later, and kept patching through September. JCE said version 3.0 would drop official Joomla 3 support, then published a free security patch and was still releasing the 2.9.99 line for Joomla 3 in September 2026.

A third group has no fixed Joomla 3 release to offer. Fabrik says it will not backport security work to Fabrik 3, and for the 2026 calc element flaw it posted a one-line manual patch in its forum, as-is with no warranty. Phoca has published nothing about Joomla 3, and its newest Phoca Cart release offered to Joomla 3 sites dates from October 2021. On the Page Builder CK Joomla 3 branch, the rule below records no fixed version for the file upload flaw. The route to a patched build is to move the site to a supported Joomla.

The vendors page lists every vendor we have checked, with the dated statement and the source for each.

Find out which of these your sites actually run

mySites.guru reads the extensions installed on every connected site and matches them against these rules on each snapshot. Connect one Joomla 3 site and the first audit is free, with no card.

Every rule, grouped by extension

Extensions with the most severe rules come first, and within each extension the most severe and most recent rule leads. Some rules cover a Joomla 4 to 6 branch of the same extension, because one disclosure often produces a rule per branch.

J2Store / J2Commerce (7 rules)

J2Commerce and Joomla 3 · All J2Store / J2Commerce rules on mySites.guru

Page Builder CK (5 rules)

All Page Builder CK rules on mySites.guru

  • Critical

    Page Builder CK (com_pagebuilderck) 3.1.1 to 3.1.3 - Authenticated Arbitrary File Upload (RCE)

    Affected ≥ 3.1.1 and < 3.1.4 · Published 22 Jul 2026

    CVE-2026-63048

  • Critical

    Page Builder CK (com_pagebuilderck) 3.3.0 to 3.4.12 - Authenticated Arbitrary File Upload (RCE)

    Affected ≥ 3.3.0 and < 3.4.13 · Published 22 Jul 2026

    CVE-2026-63048

  • Critical

    Page Builder CK (com_pagebuilderck) below 3.1.1 - Unauthenticated Arbitrary File Upload (RCE, CVE-2026-56290)

    Affected < 3.1.1 · No publication date on file

    CVE-2026-56290

  • Critical

    Page Builder CK (com_pagebuilderck) 3.4.0 to 3.4.9 - Unauthenticated Arbitrary File Upload (RCE, CVE-2026-56290)

    Affected ≥ 3.4.0 and < 3.4.10 · No publication date on file

    CVE-2026-56290

  • Critical

    Page Builder CK (com_pagebuilderck) 3.5.0 to 3.5.x - Unauthenticated Arbitrary File Upload (RCE, CVE-2026-56290)

    Affected ≥ 3.5.0 and < 3.6.0 · No publication date on file

    CVE-2026-56290

Events Booking (3 rules)

JoomDonation and Joomla 3 · All Events Booking rules on mySites.guru

  • Critical

    Events Booking (com_eventbooking) 5.x below 5.8.1 - Unauthenticated File Upload and User Enumeration (CVE-2026-58149, CVE-2026-60024, CVE-2026-60025)

    Affected ≥ 5.0.0 and < 5.8.1 · Published 15 Jul 2026

    CVE-2026-58149, CVE-2026-60024, CVE-2026-60025

  • Critical

    Events Booking (com_eventbooking) below 4.9.5 - Unauthenticated File Upload and User Enumeration (CVE-2026-58149, CVE-2026-60024, CVE-2026-60025)

    Affected < 4.9.5 · Published 15 Jul 2026

    CVE-2026-58149, CVE-2026-60024, CVE-2026-60025

  • Medium

    Events Booking (com_eventbooking) 5.x below 5.8.2 - Unauthenticated Invoice IDOR (billing data disclosure, fixed 5.8.2, CVE-2026-63047)

    Affected ≥ 5.0.0 and < 5.8.2 · Published 20 Jul 2026

    CVE-2026-63047

Phoca Cart (2 rules)

Phoca and Joomla 3 · All Phoca Cart rules on mySites.guru

  • Critical

    Phoca Cart (com_phocacart) 3.x - Unauthenticated SQL Injection in the product filter, no fixed release (CVE-2026-74251)

    Affected ≥ 3.0.0 and < 4.0.0 · No publication date on file

    CVE-2026-74251

  • High

    Phoca Cart (com_phocacart) below 6.1.9 - Unauthenticated Order Download IDOR (paid file disclosure)

    Affected ≥ 3.0.0 and < 6.1.9 · Published 1 Oct 2026

SP Page Builder (2 rules)

JoomShaper and Joomla 3 · All SP Page Builder rules on mySites.guru

  • Critical

    SP Page Builder (com_sppagebuilder) 4.0.0 to 6.6.1 - CVE-2026-48908 (CVSS 10.0) Unauthenticated Arbitrary File Upload (RCE)

    Affected ≥ 4.0.0 and < 6.6.2 · Published 14 Jun 2026

    CVE-2026-48908

  • High

    SP Page Builder (com_sppagebuilder) 6.8.0 to 6.9.0 - CVE-2026-78375 Author-level SQL Injection (full database read, CVSS 8.6), CVE-2026-79700 and CVE-2026-79701 Unauthenticated Captcha Bypass, plus three authorisation flaws - fixed in 6.9.1

    Affected ≥ 6.8.0 and < 6.9.1 · Published 14 Sept 2026

    CVE-2026-78375, CVE-2026-79700, CVE-2026-79701, CVE-2026-81564, CVE-2026-81565, CVE-2026-81566

UP Universal Plugin (2 rules)

All UP Universal Plugin rules on mySites.guru

  • Critical

    UP Universal Plugin (plg_content_up) 5.0.0 to 6.0.29 - Unauthenticated Remote Code Installation, File Read, SQL Injection and PHP Injection (CVE-2026-97160, CVE-2026-97161, CVE-2026-97162, CVE-2026-97163)

    Affected ≥ 5.0.0 and < 5.2.1 · Published 26 Sept 2026

    CVE-2026-97160, CVE-2026-97161, CVE-2026-97162, CVE-2026-97163

  • Critical

    UP Universal Plugin (plg_content_up) 5.0.0 to 6.0.29 - Unauthenticated Remote Code Installation, File Read, SQL Injection and PHP Injection (CVE-2026-97160, CVE-2026-97161, CVE-2026-97162, CVE-2026-97163)

    Affected ≥ 6.0.0 and < 6.1.0 · Published 26 Sept 2026

    CVE-2026-97160, CVE-2026-97161, CVE-2026-97162, CVE-2026-97163

JCE (1 rule)

JCE and Joomla 3 · All JCE rules on mySites.guru

  • Critical

    JCE (com_jce) below 2.9.99.6 - Unauthenticated Arbitrary File Upload (RCE) and Directory Traversal

    Affected ≥ 2.7.0 and < 2.9.99.6 · Published 8 Jun 2026

    CVE-2026-48907

JooDatabase (1 rule)

  • Critical

    JooDatabase (com_joodb) below 5.1 - Unauthenticated SQL Injection

    Affected < 5.1.0 · Published 3 Sept 2026

    CVE-2026-78080

Phoca Download (1 rule)

Phoca and Joomla 3 · All Phoca Download rules on mySites.guru

  • Critical

    Phoca Download (com_phocadownload) 3.x and earlier - Authenticated Arbitrary File Upload (RCE), no fixed release for Joomla 3 (CVE-2026-57828, CVSS 9.0 Critical)

    Affected < 4.0.0 · Published 10 Jul 2026

    CVE-2026-57828

DPCalendar (5 rules)

Digital Peak and Joomla 3 · All DPCalendar rules on mySites.guru

  • High

    DPCalendar (com_dpcalendar) 7.0.0 to 8.19.5 (Joomla 3) - Authenticated Stored Cross-Site Scripting

    Affected ≥ 7.0.0 and < 8.19.6 · Published 28 Aug 2026

    CVE-2026-78071

  • High

    DPCalendar (com_dpcalendar) 9.0 to 10.11.1 (Joomla 4 to 6) - Unauthenticated Blind SQL Injection

    Affected ≥ 9.0.0 and < 10.11.2 · Published 13 Jul 2026

    CVE-2026-57831

  • High

    DPCalendar (com_dpcalendar) 8.18.0 to 8.19.3 (Joomla 3) - Unauthenticated Blind SQL Injection

    Affected ≥ 8.18.0 and < 8.19.4 · Published 13 Jul 2026

    CVE-2026-57831

  • Medium

    DPCalendar (com_dpcalendar) 5.5.0 to 8.19.4 (Joomla 3) - Authenticated Blind SQL Injection

    Affected ≥ 5.5.0 and < 8.19.5 · Published 28 Aug 2026

    CVE-2026-78070

  • Medium

    DPCalendar (com_dpcalendar) 9.0.0 to 10.11.2 (Joomla 4 to 6) - Authenticated Blind SQL Injection

    Affected ≥ 9.0.0 and ≤ 10.11.2 · Published 28 Aug 2026

    CVE-2026-78070

Convert Forms (4 rules)

Tassos and Joomla 3 · All Convert Forms rules on mySites.guru

  • High

    Convert Forms (com_convertforms) 4.4.10 to 4.4.15 (Joomla 3 branch) - Unauthenticated Submission Disclosure

    Affected ≥ 4.4.10 and < 4.4.16 · Published 23 Jul 2026

    CVE-2026-65758

  • Unrated

    Convert Forms (com_convertforms) 5.0.0 to 5.2.2 (Joomla 4/5/6 branch) - Unauthenticated Submission Disclosure

    Affected ≥ 5.0.0 and ≤ 5.2.2 · No publication date on file

  • Unrated

    Convert Forms (com_convertforms) 5.2.3 to 5.2.4 (Joomla 4/5/6 branch) - Unauthenticated Client-Controlled Validation Bypass (CAPTCHA and field validation bypass, CVE-2026-77026)

    Affected ≥ 5.2.3 and < 5.2.5 · No publication date on file

    CVE-2026-77026

  • Unrated

    Convert Forms (com_convertforms) 4.4.16 (Joomla 3 branch) - Unauthenticated Client-Controlled Validation Bypass (CAPTCHA and field validation bypass, CVE-2026-77026)

    Affected ≥ 4.4.16 and < 4.4.17 · No publication date on file

    CVE-2026-77026

Helix Ultimate (2 rules)

JoomShaper and Joomla 3 · All Helix Ultimate rules on mySites.guru

  • High

    Helix Ultimate (shaper_helixultimate) 2.2.7 to 2.2.9 - Media Upload Bypass, Path Traversal, Broken Access Control and Stored XSS

    Affected ≥ 2.2.7 and < 2.2.10 · Published 31 Aug 2026

    CVE-2026-78075, CVE-2026-78076, CVE-2026-78077, CVE-2026-78078, CVE-2026-78079

  • Unrated

    Helix Ultimate (shaper_helixultimate) below 2.1.4-j3sec - Unauthenticated Broken Access Control (Stored XSS and Super-User Creation via Mega Menu) - free JoomShaper security patch available

    Affected < 2.1.4-j3sec · No publication date on file

Helix Ultimate Framework (2 rules)

JoomShaper and Joomla 3 · All Helix Ultimate Framework rules on mySites.guru

  • High

    Helix Ultimate Framework (helixultimate) 2.2.7 to 2.2.9 - Media Upload Bypass, Path Traversal, Broken Access Control and Stored XSS

    Affected ≥ 2.2.7 and < 2.2.10 · Published 31 Aug 2026

    CVE-2026-78075, CVE-2026-78076, CVE-2026-78077, CVE-2026-78078, CVE-2026-78079

  • Unrated

    Helix Ultimate Framework (helixultimate) below 2.1.4-j3sec - Unauthenticated Broken Access Control (Stored XSS and Super-User Creation via Mega Menu) - free JoomShaper security patch available

    Affected < 2.1.4-j3sec · No publication date on file

Phoca Commander (2 rules)

Phoca and Joomla 3 · All Phoca Commander rules on mySites.guru

  • High

    Phoca Commander (com_phocacommander) below 6.1.2 - Authenticated Arbitrary File Write (RCE), Arbitrary File Read and Reflected XSS

    Affected < 6.1.2 · Published 27 Jul 2026

    CVE-2026-65764, CVE-2026-65765, CVE-2025-54473

  • Unrated

    Phoca Commander (com_phocacommander) 6.1.2 to 6.1.3 - Authenticated Path Traversal: Arbitrary File Read, Upload, Delete, Copy and Move (CVE-2026-66491, CVE-2026-66492, CVE-2026-66493)

    Affected ≥ 6.1.2 and < 6.1.4 · No publication date on file

    CVE-2026-66491, CVE-2026-66492, CVE-2026-66493

Sexy Polling Reloaded (2 rules)

All Sexy Polling Reloaded rules on mySites.guru

  • High

    Sexy Polling Reloaded (com_sexypolling) below 5.0.6.1 (Joomla 3.10 and 4) - Unauthenticated Blind SQL Injection

    Affected ≥ 1.0.0 and < 5.0.6.1 · Published 28 Aug 2026

    CVE-2026-78072

  • High

    Sexy Polling Reloaded (com_sexypolling) 5.1.0 to 5.6.0 (Joomla 4 to 6) - Unauthenticated Blind SQL Injection

    Affected ≥ 5.1.0 and < 5.6.1 · Published 28 Aug 2026

    CVE-2026-78072

YOOtheme Pro (2 rules)

YOOtheme and Joomla 3 · All YOOtheme Pro rules on mySites.guru

  • High

    YOOtheme Pro (yootheme) below 4.5.34 - Authenticated SQL Injection (CVSS 8.6), Arbitrary File Read (CVSS 7.0) and Broken Access Control (CVSS 5.1)

    Affected < 4.5.34 · Published 25 Aug 2026

    CVE-2026-76613, CVE-2026-75115, CVE-2026-77997

  • High

    YOOtheme Pro (yootheme) 5.0.0 to 5.0.40 - Authenticated SQL Injection (CVSS 8.6) and Arbitrary File Read (CVSS 7.0)

    Affected ≥ 5.0.0 and < 5.0.41 · Published 21 Aug 2026

    CVE-2026-76613, CVE-2026-75115

4Analytics (1 rule)

  • High

    4Analytics (com_foranalytics) below 5.0.2 - Unauthenticated Stored XSS (website takeover) (CVE-2026-58077 and CVE-2026-57833)

    Affected < 5.0.2 · Published 15 Jul 2026

    CVE-2026-58077, CVE-2026-57833

Fabrik (1 rule)

Fabrik and Joomla 3 · All Fabrik rules on mySites.guru

  • High

    Fabrik (com_fabrik) below 4.7.0 - Unauthenticated Remote Code Execution (CVE-2026-66915 and CVE-2026-67282, both CVSS 10.0)

    Affected < 4.7.0 · Published 13 May 2026

    CVE-2020-37219, CVE-2026-67282, CVE-2026-66915

JoomGallery (1 rule)

All JoomGallery rules on mySites.guru

  • High

    JoomGallery (com_joomgallery) 4.0.0 to 4.3.x - Authenticated Access to Password-Protected Content, Ownership Takeover and Stored XSS (CVE-2026-66916, CVE-2026-66917)

    Affected ≥ 4.0.0 and < 4.4.0 · Published 22 Aug 2026

    CVE-2026-66917, CVE-2026-66916

YOOtheme Pro (1 rule)

YOOtheme and Joomla 3 · All YOOtheme Pro rules on mySites.guru

  • High

    YOOtheme Pro (location) below 4.5.34 - Authenticated Stored Cross-Site Scripting via Unescaped Custom Field Value (CVSS 7.5)

    Affected ≥ 2.0.0 and < 4.5.34 · Published 25 Aug 2026

    CVE-2026-77996

ZOO (1 rule)

YOOtheme and Joomla 3 · All ZOO rules on mySites.guru

  • High

    ZOO (com_zoo) 4.1.65 - Unauthenticated Stored XSS (CVSS 8.6), Unauthenticated Arbitrary Directory Listing (6.9), Reflected XSS and Open Redirect (5.3), and Missing Front-End CSRF Protection

    Affected ≥ 4.1.65 and < 4.1.66 · Published 21 Aug 2026

    CVE-2026-76611, CVE-2026-76612, CVE-2026-77028, CVE-2026-77029

osTicky2 (1 rule)

  • Medium

    osTicky2 (com_osticky2) 2.2.8 and below - Unauthenticated Open Redirect via base64 return Parameter

    Affected ≤ 2.2.8 · Published 15 Feb 2024

    CVE-2024-21728

iCagenda (1 rule)

iCagenda and Joomla 3 · All iCagenda rules on mySites.guru

SEBLOD (1 rule)

SEBLOD and Joomla 3 · All SEBLOD rules on mySites.guru

  • Unrated

    SEBLOD (com_cck) below 3.30.0 - Unauthenticated Path Traversal Arbitrary File Download (CVE-2026-66914, CVSS 9.2)

    Affected < 3.30.0 · No publication date on file

    CVE-2026-66914

Visforms (1 rule)

All Visforms rules on mySites.guru

  • Unrated

    Visforms (com_visforms) 3.0.0 below 3.0.5 - SQL Injection (CVE-2023-23753)

    Affected ≥ 3.0.0 and < 3.0.5 · No publication date on file

    CVE-2023-23753

What to do with a match

The right response depends on whether a fixed Joomla 3 release exists.

Where the vendor ships a fixed Joomla 3 build, update to it. A rule that names an affected range clears on its own once the site is on a version above it. Where the vendor offers no fixed release, restrict who can reach the vulnerable feature, block the exploited request at a firewall where the rule describes one, and treat the move to a supported Joomla as the real fix. The options page covers that decision.

For JoomShaper's Helix Ultimate, Helix3 and SP Page Builder there is a one-click route inside mySites.guru: the vendor's own Joomla 3 packages, installed through Joomla's installer with a pinned checksum and a backup first. How that works.

These rules refresh with every mySites.guru vulnerability export, and connected sites are flagged within the hour. A rule you do not see here may still exist for a Joomla 4 to 6 branch, because this page lists only the rules that match a Joomla 3 branch.

Keeping Joomla 3 patched is part of the subscription

The one-click core patch, JoomShaper's Joomla 3 packages, vulnerable extension alerts and malware scanning are all included, alongside everything else mySites.guru does for Joomla and WordPress. No per-site fees, and no price increases since 2012.

Single site
£5/month
Upgrades itself to Unlimited when you add a second site
Unlimited sites
£19.99/month
Every site you manage, one price
Unlimited, yearly
£199.99/year
£16.66 a month

See the full pricing

Keep your Joomla 3 sites patched while you plan the move

One free audit of one site, no card, no time limit.

Audit a Joomla 3 site free