VYPR
Vypr IntelligenceAI-generatedAug 24, 2026· 25 CVEs

Joomla Extensions: 25 Vulnerabilities Including Critical SQLi and XSS Disclosed Together

A batch of 25 vulnerabilities, including critical SQL injection and XSS flaws, were disclosed across multiple Joomla extensions from August 20-24, 2026.

Key findings

  • 25 vulnerabilities disclosed across multiple Joomla extensions between August 20-24, 2026.
  • Critical flaws include SQL injection in Page Builder CK and Fabrik, and stored XSS in J2Store and Zoo.
  • Many vulnerabilities allow unauthenticated access, posing a significant risk to Joomla sites.
  • Patches are available for Fabrik, J2Store, Zoo, YOOtheme Pro, Page Builder CK, Phoca Download, and Phoca Cart.
  • Prompt updates are essential to mitigate risks from these widespread security issues.

On August 20-24, 2026, a significant batch of 25 vulnerabilities was disclosed across multiple Joomla extensions, impacting popular components like Page Builder CK, Fabrik, J2Store, YOOtheme Pro, Zoo, Phoca Download, and Phoca Cart. These vulnerabilities range in severity from Medium to Critical, with several allowing unauthenticated attackers to compromise Joomla websites. The disclosures highlight a broad range of security weaknesses, including SQL injection, cross-site scripting (XSS), information disclosure, and file upload vulnerabilities.

The Fabrik extension (versions prior to 4.7.2) was particularly affected, with 11 CVEs disclosed on August 22. These include critical SQL injection flaws (CVE-2026-77994, CVE-2026-76571), unauthenticated stored XSS (CVE-2026-77027), and various information disclosure vulnerabilities such as database table listing (CVE-2026-76599), directory listing (CVE-2026-76598), and disclosure of commenter emails (CVE-2026-76608). Additionally, unauthenticated file uploads to the webroot (CVE-2026-76597) and comment deletion (CVE-2026-76600) were reported.

J2Store (versions 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5) saw six vulnerabilities disclosed on August 21. Among these are a critical stored XSS in guest checkout (CVE-2026-74252), cross-customer order replication (CVE-2026-67360), and unauthenticated order content disclosure (CVE-2026-67359). Open redirect vulnerabilities (CVE-2026-67362) and unauthenticated file uploads with missing directory protection (CVE-2026-67361) were also identified.

The YOOtheme ecosystem experienced multiple disclosures on August 20 and 21. Zoo (versions prior to 4.1.66) had several issues, including unauthenticated stored XSS (CVE-2026-76612), reflected XSS and open redirect (CVE-2026-77028), and unauthenticated tag modifications (CVE-2026-76610). YOOtheme Pro (versions 1.0.0-5.0.40) was affected by an authenticated, privileged SQL injection (CVE-2026-76613).

Other affected extensions include Page Builder CK (versions < 3.6.5) with a critical second-order SQL injection (CVE-2026-77994) and a medium reflected XSS (CVE-2026-77993), disclosed on August 24. Phoca Download (versions 5.0.0-6.1.4) had a reflected XSS (CVE-2026-76569), and Phoca Cart (versions 5.0.0-6.1.7) had a reflected XSS via price parameters (CVE-2026-76565), both disclosed on August 20.

The vendor advisories indicate that patches have been released for most of these vulnerabilities. For Fabrik, versions 4.7.2 and later address the disclosed issues. J2Store versions 3.3.21, 4.0.21, and 4.1.6 are recommended. Zoo versions 4.1.65 and 4.1.66, and YOOtheme Pro 5.0.41 are also available. Users are strongly advised to update these extensions to the patched versions to mitigate the risks associated with these critical and high-severity vulnerabilities.

This coordinated disclosure event underscores the importance of regularly updating Joomla extensions. The wide range of vulnerabilities, particularly those allowing unauthenticated access and code injection, presents a significant risk to Joomla websites globally. Administrators should prioritize patching these extensions to protect their sites from potential exploitation.

The disclosed vulnerabilities include:

The patched versions are: Fabrik 4.7.2+, J2Store 3.3.21, 4.0.21, 4.1.6+, Zoo 4.1.65, 4.1.66+, YOOtheme Pro 5.0.41. Page Builder CK versions < 3.6.5 are affected, implying a fix in 3.6.5 or later. Phoca Download 6.1.5+ and Phoca Cart 6.1.8+ are the patched versions.

It is crucial for Joomla administrators to apply these updates promptly. The sheer volume and severity of these vulnerabilities, disclosed within a short period, indicate a widespread need for vigilance and proactive security management within the Joomla ecosystem.

The vulnerabilities patched include:

  • Fabrik versions prior to 4.7.2
  • J2Store versions 1.0.0-3.3.20, 4.0.0-4.0.20, 4.1.0-4.1.5
  • Zoo versions prior to 4.1.66
  • YOOtheme Pro versions 1.0.0-5.0.40
  • Page Builder CK versions < 3.6.5
  • Phoca Download versions 5.0.0-6.1.4
  • Phoca Cart versions 5.0.0-6.1.7

Users should update to the following versions or later: Fabrik 4.7.2, J2Store 3.3.21, 4.0.21, 4.1.6, Zoo 4.1.65, 4.1.66, YOOtheme Pro 5.0.41, Page Builder CK 3.6.5, Phoca Download 6.1.5, Phoca Cart 6.1.8.

This batch of vulnerabilities highlights critical security flaws across multiple popular Joomla extensions, with a significant number of them allowing unauthenticated attackers to exploit serious vulnerabilities such as SQL injection and cross-site scripting. The coordinated disclosure across multiple vendors and components emphasizes the need for prompt patching and ongoing security awareness for Joomla site administrators. The affected extensions and their fixed versions are detailed above, and immediate updates are recommended to prevent potential compromise. The Fabrik extension, in particular, suffered from a high number of vulnerabilities, including critical ones, affecting versions prior to 4.7.2. Similarly, J2Store, Zoo, and YOOtheme Pro extensions also had multiple security issues addressed in their latest releases.

The vulnerabilities disclosed are:

The patched versions are: Fabrik 4.7.2, J2Store 3.3.21, 4.0.21, 4.1.6, Zoo 4.1.65, 4.1.66, YOOtheme Pro 5.0.41, Page Builder CK 3.6.5, Phoca Download 6.1.5, Phoca Cart 6.1.8.

This coordinated disclosure event, spanning August 20-24, 2026, revealed 25 vulnerabilities across multiple Joomla extensions, including critical flaws in Fabrik, J2Store, and Page Builder CK. The vulnerabilities range from SQL injection and XSS to information disclosure and file upload flaws, many of which are exploitable by unauthenticated attackers. Administrators are urged to update affected extensions to the latest versions: Fabrik to 4.7.2+, J2Store to 3.3.21/4.0.21/4.1.6+, Zoo to 4.1.65/4.1.66+, YOOtheme Pro to 5.0.41+, Page Builder CK to 3.6.5+, Phoca Download to 6.1.5+, and Phoca Cart to 6.1.8+. Prompt patching is essential to secure Joomla websites against these widespread threats.

The vulnerabilities addressed are:

Recommended update versions: Fabrik 4.7.2, J2Store 3.3.21, 4.0.21, 4.1.6, Zoo 4.1.65, 4.1.66, YOOtheme Pro 5.0.41, Page Builder CK 3.6.5, Phoca Download 6.1.5, Phoca Cart 6.1.8.

A coordinated disclosure event from August 20-24, 2026, revealed 25 vulnerabilities across numerous Joomla extensions, including critical flaws in Fabrik, J2Store, and Page Builder CK. These vulnerabilities, ranging from SQL injection and XSS to information disclosure and file upload issues, pose a significant risk, especially as many are exploitable by unauthenticated attackers. Administrators are strongly urged to update affected extensions to the patched versions: Fabrik to 4.7.2+, J2Store to 3.3.21/4.0.21/4.1.6+, Zoo to 4.1.65/4.1.66+, YOOtheme Pro to 5.0.41+, Page Builder CK to 3.6.5+, Phoca Download to 6.1.5+, and Phoca Cart to 6.1.8+. Prompt patching is crucial for securing Joomla websites.

The vulnerabilities disclosed are:

Recommended update versions: Fabrik 4.7.2, J2Store 3.3.21, 4.0.21, 4.1.6, Zoo 4.1.65, 4.1.66, YOOtheme Pro 5.0.41, Page Builder CK 3.6.5, Phoca Download 6.1.5, Phoca Cart 6.1.8.

AI-written article. Grounded in 25 CVE records listed below.