Tag: Joomla

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days
News

iCagenda and Balbooa Forms Joomla Flaws Reportedly Exploited as Zero-Days

Following reports of zero-day exploitation in the field, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) updated its Known Exploited Vulnerabilities (KEV) database with two maximum-severity security holes affecting the iCagenda and Balbooa extensions for Joomla. The vulnerabilities listed below have both received a CVSS score of 10.0: CVE-2026-48939 is a vulnerability in the Joomla iCagenda extension that permits arbitrary files to be uploaded using the file attachment feature, resulting in the upload and execution of PHP code. CVE-2026-56291 is a flaw in the Joomla Balbooa Forms extension that permits the upload of any file, resulting in remote code execution. MySites.guru, a cloud-based dashboard service for managing WordPress and Joomla websites, claims t...
Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers
News

Backdoored Smart Slider 3 Pro Update Distributed via Compromised Nextend Servers

The update system for the Smart Slider 3 Pro plugin for WordPress and Joomla has been taken over by unknown threat actors, who have used it to distribute a malicious version with a backdoor. According to WordPress security firm Patchstack, the issue affects Smart Slider 3 Pro version 3.5.1.35 for WordPress. With over 800,000 active installations in both its free and Pro versions, Smart Slider 3 is a well-liked WordPress slider plugin. According to Nextend, a fully attacker-authored build was sent via the official update channel after an unauthorized party got access to the company's update infrastructure. A fully armed remote access toolkit was sent to any site that updated to 3.5.1.35 between its release on April 7, 2026, and its discovery about six hours later. The plugin's mai...