A security vulnerability has been identified in the Joomla extension Aimy Captcha-Less Form Guard, versions 18.0 through 20.0, distributed by aimy-extensions.com. The flaw is triggered when a specially crafted entry is sent to the extension’s “clfgd” input field. This allows an attacker to inject malicious PHP code and carry out remote code execution on your web server. Remote code execution means an unauthorized party can run arbitrary
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-65883