NewsThe Register — Security2026-07-14 11:06 UTC
Baddies caught exploiting extensions bugs with perfect 10 scores on vulnerable Joomla websites
Teaser from the source
Flaws in iCagenda, Balbooa Forms extensions can impact open source CMS that powers a million sites worldwide
This is the RSS-feed teaser. Read the full article at the original source.
Read at The Register — Security →More on exploiting
Other advisories
- CVE-2026-22313criticalThe device has a webserver that exposes a REST API authenticated with a token on the management network. By exploiting an OS command injection vulnerability …
- CVE-2022-41656mediumMissing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
- CVE-2026-49054mediumMissing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels.
- CVE-2026-48545highGradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a s…
- CVE-2026-49053mediumMissing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels.
- CVE-2026-49052mediumMissing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels.
- CVE-2026-49051mediumMissing Authorization vulnerability in Prasad Kirpekar WP Meta and Date Remover allows Exploiting Incorrectly Configured Access Control Security Levels.
- CVE-2026-49047mediumMissing Authorization vulnerability in DearHive DearFlip allows Exploiting Incorrectly Configured Access Control Security Levels.
Other news entries
- Newsbleepingcomputer2026-10-09Unpatched AhsayCBS flaws exploited to deploy webshells, mine crypto
- Newsthehackernews2026-10-09Attackers Exploit AhsayCBS Flaws to Deploy XMRig Miners Disguised as Microsoft Edge
- Newsbleepingcomputer2026-10-09Max severity SonicWall SMA1000 flaw now exploited in attacks
- Newsbleepingcomputer2026-10-09Hackers get $1,262,000 for 98 zero-days at Pwn2Own Ireland
- Newsbleepingcomputer2026-10-08OAuth grants pile up faster than you can review them. Here's how to keep up.
- Newsbleepingcomputer2026-10-08Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland
- Newsbleepingcomputer2026-10-06Ninja Forms plugin flaw exploited to hack WordPress sites
- Newsbleepingcomputer2026-10-06Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
ID