A security flaw has been found in the Aimy Captcha-Less Form Guard Joomla extension, versions 18.0 through 20.0, distributed by aimy-extensions.com. Attackers can exploit this issue by submitting a specially crafted entry in the form field named "clfgd", which lets them run unauthorized, harmful code directly on your website.
This type of vulnerability, called remote code execution, gives attackers full control over affected sites. This could lead to stolen customer or business data, defaced website content, or your site being used to serve harmful material to visitors.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-65883