Joomla Attackers Exploit 2 Extension Flaws Rated 10/10 on 1 Million Sites
Updated
Updated · The Register · Aug 24
Joomla Attackers Exploit 2 Extension Flaws Rated 10/10 on 1 Million Sites
1 articles · Updated · The Register · Aug 24
Summary
Two critical bugs in Joomla extensions iCagenda and Balbooa Forms are being exploited, with both flaws carrying maximum 10.0 severity scores.
iCagenda and Balbooa Forms are add-ons for Joomla, an open-source content management system used by about 1 million websites worldwide, widening the potential exposure.
The report identifies the extensions—not Joomla core itself—as the weak point, underscoring how third-party components can open high-risk paths into widely deployed sites.