CVE-2026-65883 (matched: php)

  • Friday, 7th August, 2026
  • 16:05pm

A security flaw has been found in the Aimy Captcha-Less Form Guard extension for Joomla, versions 18.0 through 20.0, made by aimy-extensions.com.

The vulnerability works when an attacker sends a specially crafted request using a form field named clfgd. This lets them inject malicious code into your site’s PHP systems, which can then run unauthorized commands on your web server, a type of attack known as remote code execution.

If this flaw is exploited, an attacker could gain control over parts of your site, allowing them to steal data, change your site’s public content, or use your site to harm visitors.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-65883

« Back