This security notice is for owners of Joomla websites that use the Aimy Captcha-Less Form Guard extension (versions 18.0 to 20.0) from aimy-extensions.com. A flaw exists in these specific extension versions: attackers can exploit it by sending a specially crafted entry to the "clfgd" field on forms powered by this tool.
If this flaw is exploited, it lets attackers run unauthorized, malicious code on your website’s server. This could give them full control of your site, let them steal visitor or business data, deface your public content, or use your site to harm people who visit it.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-65883