CVE-2026-65883 (matched: php)

  • Saturday, 8th August, 2026
  • 10:04am

A security vulnerability has been identified in the Aimy Captcha-Less Form Guard extension for Joomla, developed by aimy-extensions.com. The flaw impacts versions 18.0 through 20.0 of the tool.

This issue exploits PHP object injection, a technique that lets unauthorized users run harmful code on your website's hosting server. Attackers can trigger the vulnerability by submitting a specially crafted entry to the extension's "clfgd" form field.

If successfully exploited, this leads to remote code execution, meaning an attacker could gain full control of your website, access sensitive data stored on your server, or modify your site's content and features without your knowledge.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-65883

« Back