Joomla extension vulnerabilities that reach Joomla 3
The one-click core patch cannot touch your extensions, so they are a separate exposure. Each row below is a vulnerability rule in the mySites.guru database for a Joomla extension whose Joomla 3 branch is affected. 52 rules across 25 extensions, exported 2 Oct 2026.
Whether a flaw is fixable for Joomla 3 depends entirely on the vendor. Some still ship fixes for a Joomla 3 branch, some said they had stopped and kept shipping, and some never published a Joomla 3 fix at all.
Rule counts are from the mySites.guru vulnerability database, exported 2 Oct 2026. The site figure is across sites connected to mySites.guru, 28 August 2026.
Why the vendor decides what you can fix
An extension flaw is closed by an update from the vendor, and an update only exists if the vendor still builds one for Joomla 3.
Several vendors still ship Joomla 3 security releases. Digital Peak put DPCalendar 8.x into hybrid maintenance in May 2024 and shipped 8.19.4, 8.19.5 and 8.19.6 for Joomla 3 in 2026. Tassos shipped Convert Forms 4.4.16 and 4.4.17 for Joomla 3 in July and August 2026. J2Store has patched its Joomla 3 line the same day as J2Store 4, until its end of life on 19 October 2026. YOOtheme removed Joomla 3 support in Pro 5.0, yet its 4.5.x line received all four of its 2026 security fixes in August.
Others said they had stopped, then kept shipping. JoomShaper announced on 9 July 2026 that Joomla 3 would get no security patches, shipped Joomla 3 security packages for Helix Ultimate, Helix3 and SP Page Builder six days later, and kept patching through September. JCE said version 3.0 would drop official Joomla 3 support, then published a free security patch and was still releasing the 2.9.99 line for Joomla 3 in September 2026.
A third group has no fixed Joomla 3 release to offer. Fabrik says it will not backport security work to Fabrik 3, and for the 2026 calc element flaw it posted a one-line manual patch in its forum, as-is with no warranty. Phoca has published nothing about Joomla 3, and its newest Phoca Cart release offered to Joomla 3 sites dates from October 2021. On the Page Builder CK Joomla 3 branch, the rule below records no fixed version for the file upload flaw. The route to a patched build is to move the site to a supported Joomla.
The vendors page lists every vendor we have checked, with the dated statement and the source for each.
Find out which of these your sites actually run
mySites.guru reads the extensions installed on every connected site and matches them against these rules on each snapshot. Connect one Joomla 3 site and the first audit is free, with no card.
Every rule, grouped by extension
Extensions with the most severe rules come first, and within each extension the most severe and most recent rule leads. Some rules cover a Joomla 4 to 6 branch of the same extension, because one disclosure often produces a rule per branch.
J2Store / J2Commerce (7 rules)
J2Commerce and Joomla 3 · All J2Store / J2Commerce rules on mySites.guru
- Critical
J2Store / J2Commerce (com_j2store) 3.3.21 (Joomla 3 branch) - Unauthenticated Payment Callback Forgery and Cart Tampering, Backend Privilege Escalation, Guest Address IDOR and Reflected XSS (5 CVEs)
Affected ≥ 3.3.21 and < 3.3.22 · Published 31 Aug 2026
CVE-2026-77999, CVE-2026-78000, CVE-2026-78064, CVE-2026-78065, CVE-2026-78069
- Critical
J2Store / J2Commerce (com_j2store) 4.0.21 (Joomla 4.0 branch) - Unauthenticated Payment Callback Forgery and Cart Tampering, Backend Privilege Escalation, Guest Address IDOR and Reflected XSS (5 CVEs)
Affected ≥ 4.0.21 and < 4.0.22 · Published 31 Aug 2026
CVE-2026-77999, CVE-2026-78000, CVE-2026-78064, CVE-2026-78065, CVE-2026-78069
- Critical
J2Store / J2Commerce (com_j2store) 4.1.6 (Joomla 4.1 branch) - Unauthenticated Payment Callback Forgery and Cart Tampering, Backend Privilege Escalation, Guest Address IDOR and Reflected XSS (5 CVEs)
Affected ≥ 4.1.6 and < 4.1.7 · Published 31 Aug 2026
CVE-2026-77999, CVE-2026-78000, CVE-2026-78064, CVE-2026-78065, CVE-2026-78069
- High
J2Store / J2Commerce (com_j2store) 3.3.22 (Joomla 3 branch) - Unauthenticated Blind SQL Injection, Arbitrary File Read, Order Status Tampering, Forgeable Order Token and Missing CSRF Protection (6 CVEs)
Affected ≥ 3.3.22 and < 3.3.23 · Published 15 Sept 2026
CVE-2026-78081, CVE-2026-81567, CVE-2026-81568, CVE-2026-82189, CVE-2026-82190, CVE-2026-82191
- High
J2Store / J2Commerce (com_j2store) below 3.3.21 (Joomla 3 branch) - Unauthenticated File Upload (exploited in the wild), Order Data Disclosure, Stored XSS and IDOR (6 CVEs)
Affected < 3.3.21 · Published 21 Aug 2026
CVE-2026-67358, CVE-2026-67359, CVE-2026-67360, CVE-2026-67361, CVE-2026-67362, CVE-2026-74252, CVE-2020-13996
- High
J2Store / J2Commerce (com_j2store) 4.0.0 to 4.0.20 - Unauthenticated File Upload (exploited in the wild), Order Data Disclosure, Stored XSS and IDOR (6 CVEs)
Affected ≥ 4.0.0 and < 4.0.21 · Published 21 Aug 2026
CVE-2026-67358, CVE-2026-67359, CVE-2026-67360, CVE-2026-67361, CVE-2026-67362, CVE-2026-74252
- High
J2Store / J2Commerce (com_j2store) 4.1.0 to 4.1.5 - Unauthenticated File Upload (exploited in the wild), Order Data Disclosure, Stored XSS and IDOR (6 CVEs)
Affected ≥ 4.1.0 and < 4.1.6 · Published 21 Aug 2026
CVE-2026-67358, CVE-2026-67359, CVE-2026-67360, CVE-2026-67361, CVE-2026-67362, CVE-2026-74252
Page Builder CK (5 rules)
All Page Builder CK rules on mySites.guru
- Critical
Page Builder CK (com_pagebuilderck) 3.1.1 to 3.1.3 - Authenticated Arbitrary File Upload (RCE)
Affected ≥ 3.1.1 and < 3.1.4 · Published 22 Jul 2026
- Critical
Page Builder CK (com_pagebuilderck) 3.3.0 to 3.4.12 - Authenticated Arbitrary File Upload (RCE)
Affected ≥ 3.3.0 and < 3.4.13 · Published 22 Jul 2026
- Critical
Page Builder CK (com_pagebuilderck) below 3.1.1 - Unauthenticated Arbitrary File Upload (RCE, CVE-2026-56290)
Affected < 3.1.1 · No publication date on file
- Critical
Page Builder CK (com_pagebuilderck) 3.4.0 to 3.4.9 - Unauthenticated Arbitrary File Upload (RCE, CVE-2026-56290)
Affected ≥ 3.4.0 and < 3.4.10 · No publication date on file
- Critical
Page Builder CK (com_pagebuilderck) 3.5.0 to 3.5.x - Unauthenticated Arbitrary File Upload (RCE, CVE-2026-56290)
Affected ≥ 3.5.0 and < 3.6.0 · No publication date on file
Events Booking (3 rules)
JoomDonation and Joomla 3 · All Events Booking rules on mySites.guru
- Critical
Events Booking (com_eventbooking) 5.x below 5.8.1 - Unauthenticated File Upload and User Enumeration (CVE-2026-58149, CVE-2026-60024, CVE-2026-60025)
Affected ≥ 5.0.0 and < 5.8.1 · Published 15 Jul 2026
- Critical
Events Booking (com_eventbooking) below 4.9.5 - Unauthenticated File Upload and User Enumeration (CVE-2026-58149, CVE-2026-60024, CVE-2026-60025)
Affected < 4.9.5 · Published 15 Jul 2026
- Medium
Events Booking (com_eventbooking) 5.x below 5.8.2 - Unauthenticated Invoice IDOR (billing data disclosure, fixed 5.8.2, CVE-2026-63047)
Affected ≥ 5.0.0 and < 5.8.2 · Published 20 Jul 2026
Phoca Cart (2 rules)
Phoca and Joomla 3 · All Phoca Cart rules on mySites.guru
- Critical
Phoca Cart (com_phocacart) 3.x - Unauthenticated SQL Injection in the product filter, no fixed release (CVE-2026-74251)
Affected ≥ 3.0.0 and < 4.0.0 · No publication date on file
- High
Phoca Cart (com_phocacart) below 6.1.9 - Unauthenticated Order Download IDOR (paid file disclosure)
Affected ≥ 3.0.0 and < 6.1.9 · Published 1 Oct 2026
SP Page Builder (2 rules)
JoomShaper and Joomla 3 · All SP Page Builder rules on mySites.guru
- Critical
SP Page Builder (com_sppagebuilder) 4.0.0 to 6.6.1 - CVE-2026-48908 (CVSS 10.0) Unauthenticated Arbitrary File Upload (RCE)
Affected ≥ 4.0.0 and < 6.6.2 · Published 14 Jun 2026
- High
SP Page Builder (com_sppagebuilder) 6.8.0 to 6.9.0 - CVE-2026-78375 Author-level SQL Injection (full database read, CVSS 8.6), CVE-2026-79700 and CVE-2026-79701 Unauthenticated Captcha Bypass, plus three authorisation flaws - fixed in 6.9.1
Affected ≥ 6.8.0 and < 6.9.1 · Published 14 Sept 2026
CVE-2026-78375, CVE-2026-79700, CVE-2026-79701, CVE-2026-81564, CVE-2026-81565, CVE-2026-81566
UP Universal Plugin (2 rules)
All UP Universal Plugin rules on mySites.guru
- Critical
UP Universal Plugin (plg_content_up) 5.0.0 to 6.0.29 - Unauthenticated Remote Code Installation, File Read, SQL Injection and PHP Injection (CVE-2026-97160, CVE-2026-97161, CVE-2026-97162, CVE-2026-97163)
Affected ≥ 5.0.0 and < 5.2.1 · Published 26 Sept 2026
CVE-2026-97160, CVE-2026-97161, CVE-2026-97162, CVE-2026-97163
- Critical
UP Universal Plugin (plg_content_up) 5.0.0 to 6.0.29 - Unauthenticated Remote Code Installation, File Read, SQL Injection and PHP Injection (CVE-2026-97160, CVE-2026-97161, CVE-2026-97162, CVE-2026-97163)
Affected ≥ 6.0.0 and < 6.1.0 · Published 26 Sept 2026
CVE-2026-97160, CVE-2026-97161, CVE-2026-97162, CVE-2026-97163
JCE (1 rule)
JCE and Joomla 3 · All JCE rules on mySites.guru
- Critical
JCE (com_jce) below 2.9.99.6 - Unauthenticated Arbitrary File Upload (RCE) and Directory Traversal
Affected ≥ 2.7.0 and < 2.9.99.6 · Published 8 Jun 2026
JooDatabase (1 rule)
- Critical
JooDatabase (com_joodb) below 5.1 - Unauthenticated SQL Injection
Affected < 5.1.0 · Published 3 Sept 2026
Phoca Download (1 rule)
Phoca and Joomla 3 · All Phoca Download rules on mySites.guru
- Critical
Phoca Download (com_phocadownload) 3.x and earlier - Authenticated Arbitrary File Upload (RCE), no fixed release for Joomla 3 (CVE-2026-57828, CVSS 9.0 Critical)
Affected < 4.0.0 · Published 10 Jul 2026
DPCalendar (5 rules)
Digital Peak and Joomla 3 · All DPCalendar rules on mySites.guru
- High
DPCalendar (com_dpcalendar) 7.0.0 to 8.19.5 (Joomla 3) - Authenticated Stored Cross-Site Scripting
Affected ≥ 7.0.0 and < 8.19.6 · Published 28 Aug 2026
- High
DPCalendar (com_dpcalendar) 9.0 to 10.11.1 (Joomla 4 to 6) - Unauthenticated Blind SQL Injection
Affected ≥ 9.0.0 and < 10.11.2 · Published 13 Jul 2026
- High
DPCalendar (com_dpcalendar) 8.18.0 to 8.19.3 (Joomla 3) - Unauthenticated Blind SQL Injection
Affected ≥ 8.18.0 and < 8.19.4 · Published 13 Jul 2026
- Medium
DPCalendar (com_dpcalendar) 5.5.0 to 8.19.4 (Joomla 3) - Authenticated Blind SQL Injection
Affected ≥ 5.5.0 and < 8.19.5 · Published 28 Aug 2026
- Medium
DPCalendar (com_dpcalendar) 9.0.0 to 10.11.2 (Joomla 4 to 6) - Authenticated Blind SQL Injection
Affected ≥ 9.0.0 and ≤ 10.11.2 · Published 28 Aug 2026
Convert Forms (4 rules)
Tassos and Joomla 3 · All Convert Forms rules on mySites.guru
- High
Convert Forms (com_convertforms) 4.4.10 to 4.4.15 (Joomla 3 branch) - Unauthenticated Submission Disclosure
Affected ≥ 4.4.10 and < 4.4.16 · Published 23 Jul 2026
- Unrated
Convert Forms (com_convertforms) 5.0.0 to 5.2.2 (Joomla 4/5/6 branch) - Unauthenticated Submission Disclosure
Affected ≥ 5.0.0 and ≤ 5.2.2 · No publication date on file
- Unrated
Convert Forms (com_convertforms) 5.2.3 to 5.2.4 (Joomla 4/5/6 branch) - Unauthenticated Client-Controlled Validation Bypass (CAPTCHA and field validation bypass, CVE-2026-77026)
Affected ≥ 5.2.3 and < 5.2.5 · No publication date on file
- Unrated
Convert Forms (com_convertforms) 4.4.16 (Joomla 3 branch) - Unauthenticated Client-Controlled Validation Bypass (CAPTCHA and field validation bypass, CVE-2026-77026)
Affected ≥ 4.4.16 and < 4.4.17 · No publication date on file
Helix Ultimate (2 rules)
JoomShaper and Joomla 3 · All Helix Ultimate rules on mySites.guru
- High
Helix Ultimate (shaper_helixultimate) 2.2.7 to 2.2.9 - Media Upload Bypass, Path Traversal, Broken Access Control and Stored XSS
Affected ≥ 2.2.7 and < 2.2.10 · Published 31 Aug 2026
CVE-2026-78075, CVE-2026-78076, CVE-2026-78077, CVE-2026-78078, CVE-2026-78079
- Unrated
Helix Ultimate (shaper_helixultimate) below 2.1.4-j3sec - Unauthenticated Broken Access Control (Stored XSS and Super-User Creation via Mega Menu) - free JoomShaper security patch available
Affected < 2.1.4-j3sec · No publication date on file
Helix Ultimate Framework (2 rules)
JoomShaper and Joomla 3 · All Helix Ultimate Framework rules on mySites.guru
- High
Helix Ultimate Framework (helixultimate) 2.2.7 to 2.2.9 - Media Upload Bypass, Path Traversal, Broken Access Control and Stored XSS
Affected ≥ 2.2.7 and < 2.2.10 · Published 31 Aug 2026
CVE-2026-78075, CVE-2026-78076, CVE-2026-78077, CVE-2026-78078, CVE-2026-78079
- Unrated
Helix Ultimate Framework (helixultimate) below 2.1.4-j3sec - Unauthenticated Broken Access Control (Stored XSS and Super-User Creation via Mega Menu) - free JoomShaper security patch available
Affected < 2.1.4-j3sec · No publication date on file
Phoca Commander (2 rules)
Phoca and Joomla 3 · All Phoca Commander rules on mySites.guru
- High
Phoca Commander (com_phocacommander) below 6.1.2 - Authenticated Arbitrary File Write (RCE), Arbitrary File Read and Reflected XSS
Affected < 6.1.2 · Published 27 Jul 2026
- Unrated
Phoca Commander (com_phocacommander) 6.1.2 to 6.1.3 - Authenticated Path Traversal: Arbitrary File Read, Upload, Delete, Copy and Move (CVE-2026-66491, CVE-2026-66492, CVE-2026-66493)
Affected ≥ 6.1.2 and < 6.1.4 · No publication date on file
Sexy Polling Reloaded (2 rules)
All Sexy Polling Reloaded rules on mySites.guru
- High
Sexy Polling Reloaded (com_sexypolling) below 5.0.6.1 (Joomla 3.10 and 4) - Unauthenticated Blind SQL Injection
Affected ≥ 1.0.0 and < 5.0.6.1 · Published 28 Aug 2026
- High
Sexy Polling Reloaded (com_sexypolling) 5.1.0 to 5.6.0 (Joomla 4 to 6) - Unauthenticated Blind SQL Injection
Affected ≥ 5.1.0 and < 5.6.1 · Published 28 Aug 2026
YOOtheme Pro (2 rules)
YOOtheme and Joomla 3 · All YOOtheme Pro rules on mySites.guru
- High
YOOtheme Pro (yootheme) below 4.5.34 - Authenticated SQL Injection (CVSS 8.6), Arbitrary File Read (CVSS 7.0) and Broken Access Control (CVSS 5.1)
Affected < 4.5.34 · Published 25 Aug 2026
- High
YOOtheme Pro (yootheme) 5.0.0 to 5.0.40 - Authenticated SQL Injection (CVSS 8.6) and Arbitrary File Read (CVSS 7.0)
Affected ≥ 5.0.0 and < 5.0.41 · Published 21 Aug 2026
4Analytics (1 rule)
- High
4Analytics (com_foranalytics) below 5.0.2 - Unauthenticated Stored XSS (website takeover) (CVE-2026-58077 and CVE-2026-57833)
Affected < 5.0.2 · Published 15 Jul 2026
Fabrik (1 rule)
Fabrik and Joomla 3 · All Fabrik rules on mySites.guru
- High
Fabrik (com_fabrik) below 4.7.0 - Unauthenticated Remote Code Execution (CVE-2026-66915 and CVE-2026-67282, both CVSS 10.0)
Affected < 4.7.0 · Published 13 May 2026
JoomGallery (1 rule)
All JoomGallery rules on mySites.guru
- High
JoomGallery (com_joomgallery) 4.0.0 to 4.3.x - Authenticated Access to Password-Protected Content, Ownership Takeover and Stored XSS (CVE-2026-66916, CVE-2026-66917)
Affected ≥ 4.0.0 and < 4.4.0 · Published 22 Aug 2026
YOOtheme Pro (1 rule)
YOOtheme and Joomla 3 · All YOOtheme Pro rules on mySites.guru
- High
YOOtheme Pro (location) below 4.5.34 - Authenticated Stored Cross-Site Scripting via Unescaped Custom Field Value (CVSS 7.5)
Affected ≥ 2.0.0 and < 4.5.34 · Published 25 Aug 2026
ZOO (1 rule)
YOOtheme and Joomla 3 · All ZOO rules on mySites.guru
- High
ZOO (com_zoo) 4.1.65 - Unauthenticated Stored XSS (CVSS 8.6), Unauthenticated Arbitrary Directory Listing (6.9), Reflected XSS and Open Redirect (5.3), and Missing Front-End CSRF Protection
Affected ≥ 4.1.65 and < 4.1.66 · Published 21 Aug 2026
CVE-2026-76611, CVE-2026-76612, CVE-2026-77028, CVE-2026-77029
osTicky2 (1 rule)
- Medium
osTicky2 (com_osticky2) 2.2.8 and below - Unauthenticated Open Redirect via base64 return Parameter
Affected ≤ 2.2.8 · Published 15 Feb 2024
iCagenda (1 rule)
iCagenda and Joomla 3 · All iCagenda rules on mySites.guru
- Unrated
iCagenda (com_icagenda) 4.0.8 to 4.0.11 - Unauthenticated SQL Injection (CVE-2026-67365)
Affected ≥ 4.0.8 and < 4.0.12 · No publication date on file
CVE-2026-67365, CVE-2026-71571, CVE-2026-67366, CVE-2026-71570
SEBLOD (1 rule)
SEBLOD and Joomla 3 · All SEBLOD rules on mySites.guru
- Unrated
SEBLOD (com_cck) below 3.30.0 - Unauthenticated Path Traversal Arbitrary File Download (CVE-2026-66914, CVSS 9.2)
Affected < 3.30.0 · No publication date on file
Visforms (1 rule)
All Visforms rules on mySites.guru
- Unrated
Visforms (com_visforms) 3.0.0 below 3.0.5 - SQL Injection (CVE-2023-23753)
Affected ≥ 3.0.0 and < 3.0.5 · No publication date on file
What to do with a match
The right response depends on whether a fixed Joomla 3 release exists.
Where the vendor ships a fixed Joomla 3 build, update to it. A rule that names an affected range clears on its own once the site is on a version above it. Where the vendor offers no fixed release, restrict who can reach the vulnerable feature, block the exploited request at a firewall where the rule describes one, and treat the move to a supported Joomla as the real fix. The options page covers that decision.
For JoomShaper's Helix Ultimate, Helix3 and SP Page Builder there is a one-click route inside mySites.guru: the vendor's own Joomla 3 packages, installed through Joomla's installer with a pinned checksum and a backup first. How that works.
These rules refresh with every mySites.guru vulnerability export, and connected sites are flagged within the hour. A rule you do not see here may still exist for a Joomla 4 to 6 branch, because this page lists only the rules that match a Joomla 3 branch.
Keeping Joomla 3 patched is part of the subscription
The one-click core patch, JoomShaper's Joomla 3 packages, vulnerable extension alerts and malware scanning are all included, alongside everything else mySites.guru does for Joomla and WordPress. No per-site fees, and no price increases since 2012.
Keep your Joomla 3 sites patched while you plan the move
One free audit of one site, no card, no time limit.