CVE-2026-65883 (matched: php)

  • Thursday, 6th August, 2026
  • 22:05pm

A security flaw has been identified in the Aimy Captcha-Less Form Guard extension for Joomla, created by aimy-extensions.com, that impacts versions 18.0 through 20.0. This issue lets attackers use a specially crafted entry in the form’s "clfgd" field to run their own malicious code directly on your website, a type of attack known as remote code execution.

If your site uses this specific Joomla extension, an attacker could exploit this flaw to take full control of your site without needing your account login credentials. That could allow them to steal private data stored on your site, alter your site’s public content, redirect visitors to harmful pages, or use your hosting resources for unauthorized activity.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-65883

« Back