A security flaw has been identified in the Aimy Captcha-Less Form Guard extension for Joomla, developed by aimy-extensions.com. The vulnerability impacts versions 18.0 through 20.0 of the extension.
The issue stems from how the extension processes a specific form input field labeled "clfgd". Attackers can submit a specially crafted, forged value in this field to inject malicious PHP code into your site, enabling remote code execution.
If exploited, this could allow an unauthorized actor to run commands on your website without your permission. This may lead to full control of your site, theft of data from your site or its visitors, unwanted changes to your site’s content, or your site being used to spread harmful material to other users.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-65883