A security vulnerability has been identified in the Aimy Captcha-Less Form Guard extension for Joomla, versions 18.0 to 20.0, sold by aimy-extensions.com. The flaw allows bad actors to send a specially crafted value in the form's "clfgd" field to inject harmful PHP code into your website, which lets them run unauthorized remote commands on your site. If your Joomla site uses this extension and is running one of the affected versions, an attacker could exploit this issue to take partial or full control of your site, steal visitor information, add malicious content, or redirect visitors to harmful pages.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-65883