Joomla Extensions: 25 Vulnerabilities Including Critical RCE, SQLi, and XSS Disclosed Together
A batch of 25 vulnerabilities, including critical RCE and SQLi, were disclosed across multiple Joomla extensions from August 22-28, 2026.

Key findings
- 25 vulnerabilities disclosed across multiple Joomla extensions between August 22-28, 2026.
- Critical flaws include RCE in Joomla Event Manager, SQLi in Page Builder CK and Fabrik, and stored XSS in DP Calendar.
- Many vulnerabilities allow unauthenticated access, posing a significant risk to Joomla sites.
- Patches are available for Fabrik, Joomla Event Manager, YOOtheme Pro, and Page Builder CK.
- Prompt updates are essential to mitigate risks from these widespread security issues.
On August 22-28, 2026, a significant batch of 25 vulnerabilities was disclosed across multiple Joomla extensions, impacting popular components such as Fabrik, Joomla Event Manager, YOOtheme Pro, and Page Builder CK. These vulnerabilities, ranging from critical remote code execution and SQL injection to high and medium severity flaws, were disclosed over a six-day period, highlighting a widespread security concern for Joomla users. The disclosures include critical vulnerabilities in Fabrik (CVE-2026-76571, CVE-2026-76597, CVE-2026-76598, CVE-2026-76599, CVE-2026-76607, CVE-2026-76596, CVE-2026-76606), Joomla Event Manager (CVE-2026-77991), and Page Builder CK (CVE-2026-77994).
The vulnerabilities can be broadly categorized by the affected extensions. Fabrik, with 15 disclosed CVEs, presents a particularly alarming set of issues. These include unauthenticated SQL injection (CVE-2026-76571), arbitrary file uploads (CVE-2026-76597), path traversal (CVE-2026-76606), table truncation (CVE-2026-76596), and numerous other unauthenticated access and modification flaws (CVE-2026-77027, CVE-2026-76600, CVE-2026-76601, CVE-2026-76603, CVE-2026-76608, CVE-2026-76609, CVE-2026-76598, CVE-2026-76599, CVE-2026-76603, CVE-2026-76601, CVE-2026-76600, CVE-2026-76608, CVE-2026-76599, CVE-2026-76601, CVE-2026-76603, CVE-2026-76600, CVE-2026-76608, CVE-2026-76599).
Joomla Event Manager also saw multiple vulnerabilities disclosed, including critical remote code execution (CVE-2026-77991), cross-user event takeover (CVE-2026-77035), unauthenticated article overwrite and force-publish (CVE-2026-77034), readable attendee lists for unauthorized users (CVE-2026-77990), and reflected XSS via PDF export links (CVE-2026-77989).
Other notable disclosures include critical SQL injection in Page Builder CK (CVE-2026-77994) and reflected XSS in the same extension (CVE-2026-77993). YOOtheme Pro, a popular theme, had authenticated stored XSS (CVE-2026-77996) and information disclosure vulnerabilities (CVE-2026-77997). DP Calendar also had authenticated stored XSS (CVE-2026-78071) and blind SQL injection (CVE-2026-78070).
The batch of vulnerabilities, disclosed between August 20-24, 2026 according to related coverage, underscores the significant risks associated with unpatched Joomla extensions. Many of these flaws allow for unauthenticated access, enabling attackers to compromise sites without prior user interaction. Patches are available for several affected extensions, including Fabrik, YOOtheme Pro, Page Builder CK, and Joomla Event Manager. Users are strongly advised to update these extensions to their patched versions immediately to mitigate the risks posed by these widespread security issues.
The coordinated disclosure of these 25 vulnerabilities across multiple Joomla extensions highlights a critical need for diligent security practices among Joomla site administrators. The sheer volume and severity of these flaws, particularly those allowing unauthenticated access and remote code execution, present a substantial threat landscape. Promptly applying available patches for extensions like Fabrik (versions prior to 4.7.2), Joomla Event Manager (versions prior to 5.0.1), YOOtheme Pro (versions prior to 5.0.41), and Page Builder CK (versions prior to 3.6.5) is paramount. Staying informed about security advisories and maintaining up-to-date extensions are essential steps in defending Joomla websites against such widespread attacks.