Tijd zoekopdracht: 2.14 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 4.165 MB Regels teruggegeven: 0
SELECT `data`
FROM `hmclx_session`
WHERE `session_id` = X'383539616c6d353261726c646539706e347470313639326b3430'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_session | const | PRIMARY | PRIMARY | 194 | const | 1 | |
| Status | Duration |
|---|
| Starting | 0.18 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.07 ms |
| After opening tables | 0.03 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.09 ms |
| Optimizing | 0.04 ms |
| Statistics | 0.15 ms |
| Preparing | 0.01 ms |
| Executing | 0.03 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 16 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 15 | JDatabaseDriver->loadResult() | JROOT/libraries/joomla/session/storage/database.php:45 |
| 14 | JSessionStorageDatabase->read() | Zelfde als de call in onderstaande regel. |
| 13 | session_start() | JROOT/libraries/joomla/session/handler/native.php:260 |
| 12 | JSessionHandlerNative->doSessionStart() | JROOT/libraries/joomla/session/handler/native.php:50 |
| 11 | JSessionHandlerNative->start() | JROOT/libraries/joomla/session/handler/joomla.php:88 |
| 10 | JSessionHandlerJoomla->start() | JROOT/libraries/src/Session/Session.php:661 |
| 9 | Joomla\CMS\Session\Session->_start() | JROOT/libraries/src/Session/Session.php:621 |
| 8 | Joomla\CMS\Session\Session->start() | JROOT/libraries/src/Session/Session.php:499 |
| 7 | Joomla\CMS\Session\Session->get() | JROOT/libraries/src/Session/Session.php:456 |
| 6 | Joomla\CMS\Session\Session->isNew() | JROOT/libraries/src/Application/CMSApplication.php:826 |
| 5 | Joomla\CMS\Application\CMSApplication->loadSession() | JROOT/libraries/src/Application/CMSApplication.php:136 |
| 4 | Joomla\CMS\Application\CMSApplication->__construct() | JROOT/libraries/src/Application/SiteApplication.php:66 |
| 3 | Joomla\CMS\Application\SiteApplication->__construct() | JROOT/libraries/src/Application/CMSApplication.php:386 |
| 2 | Joomla\CMS\Application\CMSApplication::getInstance() | JROOT/libraries/src/Factory.php:140 |
| 1 | Joomla\CMS\Factory::getApplication() | JROOT/index.php:46 |
Tijd zoekopdracht: 0.87 ms Na de laatste zoekopdracht: 3.96 ms Zoekopdracht geheugen: 0.020 MB geheugen voor zoekopdracht: 4.261 MB Regels teruggegeven: 0
SELECT `session_id`
FROM `hmclx_session`
WHERE `session_id` = X'383539616c6d353261726c646539706e347470313639326b3430'
LIMIT 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_session | const | PRIMARY | PRIMARY | 194 | const | 1 | Using index |
| Status | Duration |
|---|
| Starting | 0.12 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.05 ms |
| After opening tables | 0.22 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.05 ms |
| Optimizing | 0.03 ms |
| Statistics | 0.09 ms |
| Preparing | 0.01 ms |
| Executing | 0.03 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.01 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 9 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 8 | JDatabaseDriver->loadResult() | JROOT/libraries/src/Session/MetadataManager.php:74 |
| 7 | Joomla\CMS\Session\MetadataManager->createRecordIfNonExisting() | JROOT/libraries/src/Application/CMSApplication.php:154 |
| 6 | Joomla\CMS\Application\CMSApplication->checkSession() | JROOT/libraries/src/Application/CMSApplication.php:828 |
| 5 | Joomla\CMS\Application\CMSApplication->loadSession() | JROOT/libraries/src/Application/CMSApplication.php:136 |
| 4 | Joomla\CMS\Application\CMSApplication->__construct() | JROOT/libraries/src/Application/SiteApplication.php:66 |
| 3 | Joomla\CMS\Application\SiteApplication->__construct() | JROOT/libraries/src/Application/CMSApplication.php:386 |
| 2 | Joomla\CMS\Application\CMSApplication::getInstance() | JROOT/libraries/src/Factory.php:140 |
| 1 | Joomla\CMS\Factory::getApplication() | JROOT/index.php:46 |
Tijd zoekopdracht: 1.42 ms Na de laatste zoekopdracht: 0.26 ms Zoekopdracht geheugen: 0.004 MB geheugen voor zoekopdracht: 4.266 MB
INSERT INTO `hmclx_session`
(`session_id`,`guest`,`time`,`userid`,`username`,`client_id`)
VALUES
(X'383539616c6d353261726c646539706e347470313639326b3430', 1, 1785615663, 0, '', 0)
VERKLAREN niet mogelijk voor zoekopdracht: INSERT INTO `hmclx_session`
(`session_id`,`guest`,`time`,`userid`,`username`,`client_id`) VALUES
(X'383539616c6d353261726c646539706e347470313639326b3430', 1, 1785615663, 0, '', 0)
| Status | Duration |
|---|
| Starting | 0.08 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init for update | 0.02 ms |
| Update | 0.18 ms |
| Waiting for query cache lock | 0.00 ms |
| Update | 0.01 ms |
| End of update loop | 0.00 ms |
| Query end | 0.01 ms |
| Commit | 0.67 ms |
| Query end | 0.01 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 8 | JDatabaseDriverMysqli->execute() | JROOT/libraries/src/Session/MetadataManager.php:116 |
| 7 | Joomla\CMS\Session\MetadataManager->createRecordIfNonExisting() | JROOT/libraries/src/Application/CMSApplication.php:154 |
| 6 | Joomla\CMS\Application\CMSApplication->checkSession() | JROOT/libraries/src/Application/CMSApplication.php:828 |
| 5 | Joomla\CMS\Application\CMSApplication->loadSession() | JROOT/libraries/src/Application/CMSApplication.php:136 |
| 4 | Joomla\CMS\Application\CMSApplication->__construct() | JROOT/libraries/src/Application/SiteApplication.php:66 |
| 3 | Joomla\CMS\Application\SiteApplication->__construct() | JROOT/libraries/src/Application/CMSApplication.php:386 |
| 2 | Joomla\CMS\Application\CMSApplication::getInstance() | JROOT/libraries/src/Factory.php:140 |
| 1 | Joomla\CMS\Factory::getApplication() | JROOT/index.php:46 |
Tijd zoekopdracht: 1.73 ms Na de laatste zoekopdracht: 6.69 ms Zoekopdracht geheugen: 0.165 MB geheugen voor zoekopdracht: 4.454 MB Regels teruggegeven: 43
SELECT `extension_id` AS `id`,`element` AS `option`,`params`,`enabled`
FROM `hmclx_extensions`
WHERE `type` = 'component'
AND `state` = 0
AND `enabled` = 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_extensions | ref | extension | extension | 82 | const | 43 | Using index condition; Using where |
| Status | Duration |
|---|
| Starting | 0.16 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.05 ms |
| After opening tables | 0.02 ms |
| System lock | 0.01 ms |
| table lock | 0.04 ms |
| init | 0.08 ms |
| Optimizing | 0.07 ms |
| Statistics | 0.25 ms |
| Preparing | 0.09 ms |
| Executing | 0.01 ms |
| Sending data | 0.60 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.02 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.01 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.01 ms |
| Freeing items | 0.03 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 12 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 11 | JDatabaseDriver->loadObjectList() | JROOT/libraries/src/Component/ComponentHelper.php:445 |
| 10 | Joomla\CMS\Component\ComponentHelper::Joomla\CMS\Component\{closure}() | Zelfde als de call in onderstaande regel. |
| 9 | call_user_func_array() | JROOT/libraries/src/Cache/Controller/CallbackController.php:173 |
| 8 | Joomla\CMS\Cache\Controller\CallbackController->get() | JROOT/libraries/src/Component/ComponentHelper.php:453 |
| 7 | Joomla\CMS\Component\ComponentHelper::load() | JROOT/libraries/src/Component/ComponentHelper.php:519 |
| 6 | Joomla\CMS\Component\ComponentHelper::getComponents() | JROOT/libraries/src/Component/ComponentHelper.php:44 |
| 5 | Joomla\CMS\Component\ComponentHelper::getComponent() | JROOT/libraries/src/Component/ComponentHelper.php:103 |
| 4 | Joomla\CMS\Component\ComponentHelper::getParams() | JROOT/libraries/src/Application/SiteApplication.php:594 |
| 3 | Joomla\CMS\Application\SiteApplication->initialiseApp() | JROOT/libraries/src/Application/SiteApplication.php:212 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.17 ms Na de laatste zoekopdracht: 9.50 ms Zoekopdracht geheugen: 0.021 MB geheugen voor zoekopdracht: 4.781 MB Regels teruggegeven: 6
SELECT id, rules
FROM `hmclx_viewlevels`
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_viewlevels | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 6 | |
| Status | Duration |
|---|
| Starting | 0.19 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.09 ms |
| After opening tables | 0.02 ms |
| System lock | 0.01 ms |
| table lock | 0.03 ms |
| init | 0.06 ms |
| Optimizing | 0.03 ms |
| Statistics | 0.06 ms |
| Preparing | 0.05 ms |
| Executing | 0.01 ms |
| Sending data | 0.17 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.02 ms |
| Query end | 0.01 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.01 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.04 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 10 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1506 |
| 9 | JDatabaseDriver->loadAssocList() | JROOT/libraries/src/Access/Access.php:1063 |
| 8 | Joomla\CMS\Access\Access::getAuthorisedViewLevels() | JROOT/libraries/src/User/User.php:458 |
| 7 | Joomla\CMS\User\User->getAuthorisedViewLevels() | JROOT/libraries/src/Plugin/PluginHelper.php:318 |
| 6 | Joomla\CMS\Plugin\PluginHelper::load() | JROOT/libraries/src/Plugin/PluginHelper.php:87 |
| 5 | Joomla\CMS\Plugin\PluginHelper::getPlugin() | JROOT/libraries/src/Plugin/PluginHelper.php:129 |
| 4 | Joomla\CMS\Plugin\PluginHelper::isEnabled() | JROOT/libraries/src/Application/SiteApplication.php:604 |
| 3 | Joomla\CMS\Application\SiteApplication->initialiseApp() | JROOT/libraries/src/Application/SiteApplication.php:212 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.64 ms Na de laatste zoekopdracht: 0.34 ms Zoekopdracht geheugen: 0.021 MB geheugen voor zoekopdracht: 4.794 MB Regels teruggegeven: 1
SELECT b.id
FROM hmclx_usergroups AS a
LEFT JOIN hmclx_usergroups AS b
ON b.lft <= a.lft
AND b.rgt >= a.rgt
WHERE a.id = 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | a | const | PRIMARY | PRIMARY | 4 | const | 1 | |
| 1 | SIMPLE | b | range | idx_usergroup_nested_set_lookup | idx_usergroup_nested_set_lookup | 4 | NULL | 1 | Using where; Using index |
| Status | Duration |
|---|
| Starting | 0.64 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.04 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.06 ms |
| Optimizing | 0.04 ms |
| Statistics | 0.43 ms |
| Preparing | 0.01 ms |
| Unlocking tables | 0.01 ms |
| Preparing | 0.08 ms |
| Executing | 0.00 ms |
| Sending data | 0.06 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.01 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 11 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1550 |
| 10 | JDatabaseDriver->loadColumn() | JROOT/libraries/src/Access/Access.php:980 |
| 9 | Joomla\CMS\Access\Access::getGroupsByUser() | JROOT/libraries/src/Access/Access.php:1095 |
| 8 | Joomla\CMS\Access\Access::getAuthorisedViewLevels() | JROOT/libraries/src/User/User.php:458 |
| 7 | Joomla\CMS\User\User->getAuthorisedViewLevels() | JROOT/libraries/src/Plugin/PluginHelper.php:318 |
| 6 | Joomla\CMS\Plugin\PluginHelper::load() | JROOT/libraries/src/Plugin/PluginHelper.php:87 |
| 5 | Joomla\CMS\Plugin\PluginHelper::getPlugin() | JROOT/libraries/src/Plugin/PluginHelper.php:129 |
| 4 | Joomla\CMS\Plugin\PluginHelper::isEnabled() | JROOT/libraries/src/Application/SiteApplication.php:604 |
| 3 | Joomla\CMS\Application\SiteApplication->initialiseApp() | JROOT/libraries/src/Application/SiteApplication.php:212 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.63 ms Na de laatste zoekopdracht: 1.78 ms Zoekopdracht geheugen: 0.031 MB geheugen voor zoekopdracht: 4.863 MB Regels teruggegeven: 123
SELECT `folder` AS `type`,`element` AS `name`,`params` AS `params`,`extension_id` AS `id`
FROM hmclx_extensions
WHERE enabled = 1
AND type = 'plugin'
AND state IN (0,1)
AND access IN (1,1,7)
ORDER BY ordering
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_extensions | ALL | extension | INDEX KEY ONTBREEKT | NULL | NULL | 270 | Using where; Gebruikt bestandssortering |
| Status | Duration |
|---|
| Starting | 0.17 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.14 ms |
| Optimizing | 0.04 ms |
| Statistics | 0.09 ms |
| Preparing | 0.02 ms |
| Sorting result | 0.01 ms |
| Executing | 0.02 ms |
| Sending data | 0.01 ms |
| Creating sort index | 0.74 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.01 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.04 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 11 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 10 | JDatabaseDriver->loadObjectList() | JROOT/libraries/src/Plugin/PluginHelper.php:351 |
| 9 | Joomla\CMS\Plugin\PluginHelper::Joomla\CMS\Plugin\{closure}() | Zelfde als de call in onderstaande regel. |
| 8 | call_user_func_array() | JROOT/libraries/src/Cache/Controller/CallbackController.php:173 |
| 7 | Joomla\CMS\Cache\Controller\CallbackController->get() | JROOT/libraries/src/Plugin/PluginHelper.php:356 |
| 6 | Joomla\CMS\Plugin\PluginHelper::load() | JROOT/libraries/src/Plugin/PluginHelper.php:87 |
| 5 | Joomla\CMS\Plugin\PluginHelper::getPlugin() | JROOT/libraries/src/Plugin/PluginHelper.php:129 |
| 4 | Joomla\CMS\Plugin\PluginHelper::isEnabled() | JROOT/libraries/src/Application/SiteApplication.php:604 |
| 3 | Joomla\CMS\Application\SiteApplication->initialiseApp() | JROOT/libraries/src/Application/SiteApplication.php:212 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 2.03 ms Na de laatste zoekopdracht: 57.19 ms Zoekopdracht geheugen: 0.021 MB geheugen voor zoekopdracht: 7.001 MB Regels teruggegeven: 4
SELECT *
FROM hmclx_languages
WHERE published=1
ORDER BY ordering ASC
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_languages | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 4 | Using where; Gebruikt bestandssortering |
| Status | Duration |
|---|
| Starting | 0.21 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.08 ms |
| After opening tables | 0.02 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.12 ms |
| Optimizing | 0.04 ms |
| Statistics | 0.06 ms |
| Preparing | 0.05 ms |
| Sorting result | 0.02 ms |
| Executing | 0.01 ms |
| Sending data | 0.03 ms |
| Creating sort index | 0.19 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.17 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 10 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 9 | JDatabaseDriver->loadObjectList() | JROOT/libraries/src/Language/LanguageHelper.php:150 |
| 8 | Joomla\CMS\Language\LanguageHelper::getLanguages() | JROOT/plugins/system/languagefilter/languagefilter.php:96 |
| 7 | PlgSystemLanguageFilter->__construct() | JROOT/libraries/src/Plugin/PluginHelper.php:280 |
| 6 | Joomla\CMS\Plugin\PluginHelper::import() | JROOT/libraries/src/Plugin/PluginHelper.php:182 |
| 5 | Joomla\CMS\Plugin\PluginHelper::importPlugin() | JROOT/libraries/src/Application/CMSApplication.php:667 |
| 4 | Joomla\CMS\Application\CMSApplication->initialiseApp() | JROOT/libraries/src/Application/SiteApplication.php:686 |
| 3 | Joomla\CMS\Application\SiteApplication->initialiseApp() | JROOT/libraries/src/Application/SiteApplication.php:212 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.34 ms Na de laatste zoekopdracht: 0.29 ms Zoekopdracht geheugen: 0.021 MB geheugen voor zoekopdracht: 7.012 MB Regels teruggegeven: 4
SELECT `element`,`name`,`client_id`,`extension_id`
FROM `hmclx_extensions`
WHERE `type` = 'language'
AND `state` = 0
AND `enabled` = 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_extensions | ref | extension | extension | 82 | const | 6 | Using index condition; Using where |
| Status | Duration |
|---|
| Starting | 0.14 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.04 ms |
| Optimizing | 0.04 ms |
| Statistics | 0.14 ms |
| Preparing | 0.03 ms |
| Executing | 0.00 ms |
| Sending data | 0.10 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.17 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 10 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 9 | JDatabaseDriver->loadObjectList() | JROOT/libraries/src/Language/LanguageHelper.php:209 |
| 8 | Joomla\CMS\Language\LanguageHelper::getInstalledLanguages() | JROOT/plugins/system/languagefilter/languagefilter.php:110 |
| 7 | PlgSystemLanguageFilter->__construct() | JROOT/libraries/src/Plugin/PluginHelper.php:280 |
| 6 | Joomla\CMS\Plugin\PluginHelper::import() | JROOT/libraries/src/Plugin/PluginHelper.php:182 |
| 5 | Joomla\CMS\Plugin\PluginHelper::importPlugin() | JROOT/libraries/src/Application/CMSApplication.php:667 |
| 4 | Joomla\CMS\Application\CMSApplication->initialiseApp() | JROOT/libraries/src/Application/SiteApplication.php:686 |
| 3 | Joomla\CMS\Application\SiteApplication->initialiseApp() | JROOT/libraries/src/Application/SiteApplication.php:212 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.15 ms Na de laatste zoekopdracht: 13.34 ms Zoekopdracht geheugen: 0.021 MB geheugen voor zoekopdracht: 7.300 MB Regels teruggegeven: 1
SELECT `template`
FROM `hmclx_template_styles`
WHERE `client_id` = 0
AND `home` = 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_template_styles | ALL | idx_client_id,idx_client_id_home | INDEX KEY ONTBREEKT | NULL | NULL | 13 | Using where |
| Status | Duration |
|---|
| Starting | 0.15 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.06 ms |
| After opening tables | 0.02 ms |
| System lock | 0.01 ms |
| table lock | 0.03 ms |
| init | 0.09 ms |
| Optimizing | 0.06 ms |
| Statistics | 0.18 ms |
| Preparing | 0.05 ms |
| Executing | 0.01 ms |
| Sending data | 0.10 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.04 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 11 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1662 |
| 10 | JDatabaseDriver->loadObject() | JROOT/plugins/system/helix3/helix3.php:242 |
| 9 | plgSystemHelix3->getTemplateName() | JROOT/plugins/system/helix3/helix3.php:47 |
| 8 | plgSystemHelix3->onAfterInitialise() | JROOT/libraries/joomla/event/event.php:70 |
| 7 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 6 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 5 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:668 |
| 4 | Joomla\CMS\Application\CMSApplication->initialiseApp() | JROOT/libraries/src/Application/SiteApplication.php:686 |
| 3 | Joomla\CMS\Application\SiteApplication->initialiseApp() | JROOT/libraries/src/Application/SiteApplication.php:212 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 2.75 ms Na de laatste zoekopdracht: 34.36 ms Zoekopdracht geheugen: 0.024 MB geheugen voor zoekopdracht: 8.441 MB Regels teruggegeven: 51
SELECT *
FROM hmclx_rsform_config
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_rsform_config | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 51 | |
| Status | Duration |
|---|
| Starting | 0.27 ms |
| checking permissions | 0.03 ms |
| Opening tables | 0.09 ms |
| After opening tables | 0.02 ms |
| System lock | 0.02 ms |
| table lock | 0.03 ms |
| init | 0.09 ms |
| Optimizing | 0.06 ms |
| Statistics | 0.07 ms |
| Preparing | 0.08 ms |
| Executing | 0.01 ms |
| Sending data | 0.35 ms |
| End of update loop | 0.02 ms |
| Query end | 0.01 ms |
| Commit | 0.03 ms |
| Query end | 0.01 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.01 ms |
| closing tables | 0.02 ms |
| Query end | 0.03 ms |
| Starting cleanup | 0.01 ms |
| Freeing items | 0.03 ms |
| Updating status | 0.31 ms |
| Reset for next command | 0.02 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 13 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 12 | JDatabaseDriver->loadObjectList() | JROOT/administrator/components/com_rsform/helpers/config.php:50 |
| 11 | RSFormProConfig->load() | JROOT/administrator/components/com_rsform/helpers/config.php:17 |
| 10 | RSFormProConfig->__construct() | JROOT/administrator/components/com_rsform/helpers/config.php:102 |
| 9 | RSFormProConfig::getInstance() | JROOT/plugins/system/rsformdeletesubmissions/rsformdeletesubmissions.php:26 |
| 8 | plgSystemRsformdeletesubmissions->onAfterInitialise() | JROOT/libraries/joomla/event/event.php:70 |
| 7 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 6 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 5 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:668 |
| 4 | Joomla\CMS\Application\CMSApplication->initialiseApp() | JROOT/libraries/src/Application/SiteApplication.php:686 |
| 3 | Joomla\CMS\Application\SiteApplication->initialiseApp() | JROOT/libraries/src/Application/SiteApplication.php:212 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.88 ms Na de laatste zoekopdracht: 7.95 ms Zoekopdracht geheugen: 0.097 MB geheugen voor zoekopdracht: 8.640 MB Regels teruggegeven: 71
SELECT m.id, m.menutype, m.title, m.alias, m.note, m.path AS route, m.link, m.type, m.level, m.language,`m`.`browserNav`, m.access, m.params, m.home, m.img, m.template_style_id, m.component_id, m.parent_id,e.element as component
FROM hmclx_menu AS m
LEFT JOIN hmclx_extensions AS e
ON m.component_id = e.extension_id
WHERE m.published = 1
AND m.parent_id > 0
AND m.client_id = 0
ORDER BY m.lft
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | m | ALL | idx_client_id_parent_id_alias_language | INDEX KEY ONTBREEKT | NULL | NULL | 223 | Using where; Gebruikt bestandssortering |
| 1 | SIMPLE | e | eq_ref | PRIMARY | PRIMARY | 4 | dblbefit_live.m.component_id | 1 | Using where |
| Status | Duration |
|---|
| Starting | 0.22 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.06 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.07 ms |
| Optimizing | 0.06 ms |
| Statistics | 0.19 ms |
| Preparing | 0.04 ms |
| Sorting result | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.03 ms |
| Creating sort index | 0.75 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.12 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 23 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 22 | JDatabaseDriver->loadObjectList() | JROOT/libraries/src/Menu/SiteMenu.php:93 |
| 21 | Joomla\CMS\Menu\SiteMenu->Joomla\CMS\Menu\{closure}() | Zelfde als de call in onderstaande regel. |
| 20 | call_user_func_array() | JROOT/libraries/src/Cache/Controller/CallbackController.php:173 |
| 19 | Joomla\CMS\Cache\Controller\CallbackController->get() | JROOT/libraries/src/Menu/SiteMenu.php:101 |
| 18 | Joomla\CMS\Menu\SiteMenu->load() | JROOT/libraries/src/Menu/AbstractMenu.php:78 |
| 17 | Joomla\CMS\Menu\AbstractMenu->__construct() | JROOT/libraries/src/Menu/SiteMenu.php:62 |
| 16 | Joomla\CMS\Menu\SiteMenu->__construct() | JROOT/libraries/src/Menu/AbstractMenu.php:142 |
| 15 | Joomla\CMS\Menu\AbstractMenu::getInstance() | JROOT/libraries/src/Application/CMSApplication.php:417 |
| 14 | Joomla\CMS\Application\CMSApplication->getMenu() | JROOT/libraries/src/Application/SiteApplication.php:275 |
| 13 | Joomla\CMS\Application\SiteApplication->getMenu() | JROOT/libraries/src/Router/SiteRouter.php:65 |
| 12 | Joomla\CMS\Router\SiteRouter->__construct() | JROOT/libraries/src/Router/Router.php:189 |
| 11 | Joomla\CMS\Router\Router::getInstance() | JROOT/libraries/src/Application/CMSApplication.php:533 |
| 10 | Joomla\CMS\Application\CMSApplication::getRouter() | JROOT/libraries/src/Application/SiteApplication.php:403 |
| 9 | Joomla\CMS\Application\SiteApplication::getRouter() | JROOT/plugins/system/languagefilter/languagefilter.php:145 |
| 8 | PlgSystemLanguageFilter->onAfterInitialise() | JROOT/libraries/joomla/event/event.php:70 |
| 7 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 6 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 5 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:668 |
| 4 | Joomla\CMS\Application\CMSApplication->initialiseApp() | JROOT/libraries/src/Application/SiteApplication.php:686 |
| 3 | Joomla\CMS\Application\SiteApplication->initialiseApp() | JROOT/libraries/src/Application/SiteApplication.php:212 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 10.21 ms Na de laatste zoekopdracht: 29.54 ms Zoekopdracht geheugen: 0.024 MB geheugen voor zoekopdracht: 9.695 MB Regels teruggegeven: 1
SELECT `extension_id` AS `id`,`element` AS `option`,`params`,`enabled`
FROM `hmclx_extensions`
WHERE `type` = 'library'
AND `element` = 'joomla'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_extensions | ref | element_clientid,element_folder_clientid,extension | extension | 484 | const,const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.19 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.06 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.10 ms |
| Optimizing | 0.06 ms |
| Statistics | 0.25 ms |
| Preparing | 0.07 ms |
| Executing | 0.01 ms |
| Sending data | 0.14 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 4.18 ms |
| Reset for next command | 0.02 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 19 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1662 |
| 18 | JDatabaseDriver->loadObject() | JROOT/libraries/src/Helper/LibraryHelper.php:167 |
| 17 | Joomla\CMS\Helper\LibraryHelper::Joomla\CMS\Helper\{closure}() | Zelfde als de call in onderstaande regel. |
| 16 | call_user_func_array() | JROOT/libraries/src/Cache/Controller/CallbackController.php:173 |
| 15 | Joomla\CMS\Cache\Controller\CallbackController->get() | JROOT/libraries/src/Helper/LibraryHelper.php:175 |
| 14 | Joomla\CMS\Helper\LibraryHelper::loadLibrary() | JROOT/libraries/src/Helper/LibraryHelper.php:43 |
| 13 | Joomla\CMS\Helper\LibraryHelper::getLibrary() | JROOT/libraries/src/Helper/LibraryHelper.php:90 |
| 12 | Joomla\CMS\Helper\LibraryHelper::getParams() | JROOT/libraries/src/Version.php:321 |
| 11 | Joomla\CMS\Version->getMediaVersion() | JROOT/libraries/src/Factory.php:778 |
| 10 | Joomla\CMS\Factory::createDocument() | JROOT/libraries/src/Factory.php:234 |
| 9 | Joomla\CMS\Factory::getDocument() | JROOT/plugins/system/oziojquery/oziojquery.php:57 |
| 8 | plgSystemOziojquery->onAfterRoute() | JROOT/libraries/joomla/event/event.php:70 |
| 7 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 6 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 5 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:1190 |
| 4 | Joomla\CMS\Application\CMSApplication->route() | JROOT/libraries/src/Application/SiteApplication.php:796 |
| 3 | Joomla\CMS\Application\SiteApplication->route() | JROOT/libraries/src/Application/SiteApplication.php:218 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 2.69 ms Na de laatste zoekopdracht: 0.77 ms Zoekopdracht geheugen: 0.006 MB geheugen voor zoekopdracht: 9.687 MB
UPDATE `hmclx_extensions`
SET `params` = '{\"mediaversion\":\"b0336a8a9c63513e913ac4104303536c\"}'
WHERE `type` = 'library'
AND `element` = 'joomla'
VERKLAREN niet mogelijk voor zoekopdracht: UPDATE `hmclx_extensions`
SET `params` = '{\"mediaversion\":\"b0336a8a9c63513e913ac4104303536c\"}'
WHERE `type` = 'library' AND `element` = 'joomla'
| Status | Duration |
|---|
| Starting | 0.17 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.05 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init for update | 0.32 ms |
| Updating | 0.52 ms |
| End of update loop | 0.02 ms |
| Waiting for query cache lock | 0.01 ms |
| End of update loop | 0.02 ms |
| Query end | 0.01 ms |
| Commit | 0.69 ms |
| Query end | 0.01 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.01 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.05 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 14 | JDatabaseDriverMysqli->execute() | JROOT/libraries/src/Helper/LibraryHelper.php:117 |
| 13 | Joomla\CMS\Helper\LibraryHelper::saveParams() | JROOT/libraries/src/Version.php:372 |
| 12 | Joomla\CMS\Version->setMediaVersion() | JROOT/libraries/src/Version.php:331 |
| 11 | Joomla\CMS\Version->getMediaVersion() | JROOT/libraries/src/Factory.php:778 |
| 10 | Joomla\CMS\Factory::createDocument() | JROOT/libraries/src/Factory.php:234 |
| 9 | Joomla\CMS\Factory::getDocument() | JROOT/plugins/system/oziojquery/oziojquery.php:57 |
| 8 | plgSystemOziojquery->onAfterRoute() | JROOT/libraries/joomla/event/event.php:70 |
| 7 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 6 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 5 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:1190 |
| 4 | Joomla\CMS\Application\CMSApplication->route() | JROOT/libraries/src/Application/SiteApplication.php:796 |
| 3 | Joomla\CMS\Application\SiteApplication->route() | JROOT/libraries/src/Application/SiteApplication.php:218 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 5.96 ms Na de laatste zoekopdracht: 8.43 ms Zoekopdracht geheugen: 0.113 MB geheugen voor zoekopdracht: 9.870 MB Regels teruggegeven: 12
SELECT id, home, template, s.params
FROM hmclx_template_styles as s
LEFT JOIN hmclx_extensions as e
ON e.element=s.template
AND e.type='template'
AND e.client_id=s.client_id
WHERE s.client_id = 0
AND e.enabled = 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid,extension | extension | 82 | const | 7 | Using index condition; Using where |
| 1 | SIMPLE | s | ref | idx_template,idx_client_id,idx_client_id_home | idx_template | 202 | dblbefit_live.e.element | 1 | Using index condition; Using where |
| Status | Duration |
|---|
| Starting | 0.30 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.09 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.13 ms |
| Optimizing | 0.08 ms |
| Statistics | 0.32 ms |
| Preparing | 0.13 ms |
| Executing | 0.01 ms |
| Sending data | 3.90 ms |
| End of update loop | 0.03 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.02 ms |
| Query end | 0.02 ms |
| Starting cleanup | 0.01 ms |
| Freeing items | 0.03 ms |
| Updating status | 0.04 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 6 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 5 | JDatabaseDriver->loadObjectList() | JROOT/libraries/src/Application/SiteApplication.php:486 |
| 4 | Joomla\CMS\Application\SiteApplication->getTemplate() | JROOT/libraries/src/Application/SiteApplication.php:168 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 2.14 ms Na de laatste zoekopdracht: 26.00 ms Zoekopdracht geheugen: 0.028 MB geheugen voor zoekopdracht: 10.482 MB Regels teruggegeven: 43
SELECT `id`,`name`,`rules`,`parent_id`
FROM `hmclx_assets`
WHERE `name` IN ('root.1','com_actionlogs','com_acymailing','com_admin','com_ajax','com_akeeba','com_associations','com_bagallery','com_banners','com_cache','com_categories','com_checkin','com_config','com_contact','com_content','com_contenthistory','com_cpanel','com_fields','com_finder','com_htprotect','com_installer','com_jce','com_joomlaupdate','com_languages','com_login','com_mailto','com_media','com_menus','com_messages','com_modules','com_newsfeeds','com_oziogallery3','com_plugins','com_postinstall','com_privacy','com_redirect','com_rsform','com_search','com_sppagebuilder','com_spsimpleportfolio','com_tags','com_templates','com_users','com_wrapper')
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_assets | range | idx_asset_name | idx_asset_name | 202 | NULL | 44 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.36 ms |
| checking permissions | 0.03 ms |
| Opening tables | 0.13 ms |
| After opening tables | 0.02 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.15 ms |
| Optimizing | 0.04 ms |
| Statistics | 0.31 ms |
| Preparing | 0.09 ms |
| Executing | 0.01 ms |
| Sending data | 0.50 ms |
| End of update loop | 0.02 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.05 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 18 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 17 | JDatabaseDriver->loadObjectList() | JROOT/libraries/src/Access/Access.php:429 |
| 16 | Joomla\CMS\Access\Access::preloadComponents() | JROOT/libraries/src/Access/Access.php:213 |
| 15 | Joomla\CMS\Access\Access::preload() | JROOT/libraries/src/Access/Access.php:531 |
| 14 | Joomla\CMS\Access\Access::getAssetRules() | JROOT/libraries/src/Access/Access.php:183 |
| 13 | Joomla\CMS\Access\Access::check() | JROOT/libraries/src/User/User.php:398 |
| 12 | Joomla\CMS\User\User->authorise() | JROOT/components/com_sppagebuilder/models/page.php:30 |
| 11 | SppagebuilderModelPage->populateState() | JROOT/libraries/src/MVC/Model/BaseDatabaseModel.php:457 |
| 10 | Joomla\CMS\MVC\Model\BaseDatabaseModel->getState() | JROOT/components/com_sppagebuilder/models/page.php:129 |
| 9 | SppagebuilderModelPage->hit() | JROOT/components/com_sppagebuilder/controller.php:65 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.81 ms Na de laatste zoekopdracht: 3.35 ms Zoekopdracht geheugen: 0.028 MB geheugen voor zoekopdracht: 10.578 MB Regels teruggegeven: 25
SHOW FULL COLUMNS
FROM `hmclx_sppagebuilder`
VERKLAREN niet mogelijk voor zoekopdracht: SHOW FULL COLUMNS FROM `hmclx_sppagebuilder`
| Status | Duration |
|---|
| Starting | 0.09 ms |
| checking permissions | 0.01 ms |
| closing tables | 0.00 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.89 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.02 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.03 ms |
| Preparing | 0.03 ms |
| Executing | 0.01 ms |
| Filling schema table | 0.01 ms |
| Opening tables | 0.05 ms |
| After opening tables | 0.01 ms |
| checking permissions | 0.17 ms |
| closing tables | 0.01 ms |
| checking permissions | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.07 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Removing tmp table | 0.11 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 16 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 15 | JDatabaseDriver->loadObjectList() | JROOT/libraries/joomla/database/driver/mysqli.php:448 |
| 14 | JDatabaseDriverMysqli->getTableColumns() | JROOT/libraries/src/Table/Table.php:261 |
| 13 | Joomla\CMS\Table\Table->getFields() | JROOT/libraries/src/Table/Table.php:180 |
| 12 | Joomla\CMS\Table\Table->__construct() | JROOT/administrator/components/com_sppagebuilder/tables/page.php:17 |
| 11 | SppagebuilderTablePage->__construct() | JROOT/libraries/src/Table/Table.php:328 |
| 10 | Joomla\CMS\Table\Table::getInstance() | JROOT/components/com_sppagebuilder/models/page.php:130 |
| 9 | SppagebuilderModelPage->hit() | JROOT/components/com_sppagebuilder/controller.php:65 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.12 ms Na de laatste zoekopdracht: 1.74 ms Zoekopdracht geheugen: 0.116 MB geheugen voor zoekopdracht: 10.630 MB Regels teruggegeven: 1
SELECT *
FROM hmclx_sppagebuilder
WHERE `id` = '1'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_sppagebuilder | const | PRIMARY | PRIMARY | 8 | const | 1 | |
| Status | Duration |
|---|
| Starting | 0.08 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.05 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.06 ms |
| Optimizing | 0.02 ms |
| Statistics | 0.12 ms |
| Preparing | 0.00 ms |
| Unlocking tables | 0.01 ms |
| Preparing | 0.02 ms |
| Executing | 0.01 ms |
| Sending data | 0.43 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.01 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.01 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 12 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1465 |
| 11 | JDatabaseDriver->loadAssoc() | JROOT/libraries/src/Table/Table.php:747 |
| 10 | Joomla\CMS\Table\Table->load() | JROOT/components/com_sppagebuilder/models/page.php:131 |
| 9 | SppagebuilderModelPage->hit() | JROOT/components/com_sppagebuilder/controller.php:65 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.18 ms Na de laatste zoekopdracht: 0.38 ms Zoekopdracht geheugen: 0.005 MB geheugen voor zoekopdracht: 10.683 MB
UPDATE hmclx_sppagebuilder
SET `hits` = (`hits` + 1)
WHERE `id` = '1'
VERKLAREN niet mogelijk voor zoekopdracht: UPDATE hmclx_sppagebuilder
SET `hits` = (`hits` + 1)
WHERE `id` = '1'
| Status | Duration |
|---|
| Starting | 0.09 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.05 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init for update | 0.11 ms |
| Updating | 0.20 ms |
| End of update loop | 0.01 ms |
| Waiting for query cache lock | 0.00 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.56 ms |
| Query end | 0.01 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 11 | JDatabaseDriverMysqli->execute() | JROOT/libraries/src/Table/Table.php:1264 |
| 10 | Joomla\CMS\Table\Table->hit() | JROOT/components/com_sppagebuilder/models/page.php:132 |
| 9 | SppagebuilderModelPage->hit() | JROOT/components/com_sppagebuilder/controller.php:65 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.36 ms Na de laatste zoekopdracht: 3.65 ms Zoekopdracht geheugen: 0.116 MB geheugen voor zoekopdracht: 10.733 MB Regels teruggegeven: 1
SELECT a.*,l.title AS language_title,ua.name AS author_name
FROM hmclx_sppagebuilder as a
LEFT JOIN `hmclx_languages` AS l
ON l.lang_code = a.language
LEFT JOIN hmclx_users AS ua
ON ua.id = a.created_by
WHERE a.id = 1
AND a.published = 1
AND a.language in ('nl-NL','*')
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | a | const | PRIMARY | PRIMARY | 8 | const | 1 | |
| 1 | SIMPLE | l | const | idx_langcode | idx_langcode | 28 | const | 0 | Unique row not found |
| 1 | SIMPLE | ua | const | PRIMARY | PRIMARY | 4 | const | 1 | |
| Status | Duration |
|---|
| Starting | 0.13 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.10 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.12 ms |
| Optimizing | 0.05 ms |
| Statistics | 0.20 ms |
| Preparing | 0.01 ms |
| Unlocking tables | 0.01 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.49 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.02 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 14 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1662 |
| 13 | JDatabaseDriver->loadObject() | JROOT/components/com_sppagebuilder/models/page.php:83 |
| 12 | SppagebuilderModelPage->getItem() | JROOT/libraries/src/MVC/View/HtmlView.php:425 |
| 11 | Joomla\CMS\MVC\View\HtmlView->get() | JROOT/components/com_sppagebuilder/views/page/view.html.php:24 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.96 ms Na de laatste zoekopdracht: 0.81 ms Zoekopdracht geheugen: 0.024 MB geheugen voor zoekopdracht: 10.798 MB Regels teruggegeven: 48
Identieke zoekopdrachten:
#22 #23SELECT `id`
FROM `hmclx_menu`
WHERE `link` LIKE '%option=com_sppagebuilder&view=page&id=1%'
AND `published` = '1'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_menu | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 223 | Using where |
| Status | Duration |
|---|
| Starting | 0.05 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.03 ms |
| Optimizing | 0.02 ms |
| Statistics | 0.03 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.63 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 16 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 15 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/route.php:86 |
| 14 | SppagebuilderHelperRoute::getMenuItemId() | JROOT/components/com_sppagebuilder/helpers/route.php:43 |
| 13 | SppagebuilderHelperRoute::getPageRoute() | JROOT/components/com_sppagebuilder/models/page.php:89 |
| 12 | SppagebuilderModelPage->getItem() | JROOT/libraries/src/MVC/View/HtmlView.php:425 |
| 11 | Joomla\CMS\MVC\View\HtmlView->get() | JROOT/components/com_sppagebuilder/views/page/view.html.php:24 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.06 ms Na de laatste zoekopdracht: 1.26 ms Zoekopdracht geheugen: 0.024 MB geheugen voor zoekopdracht: 10.823 MB Regels teruggegeven: 48
Identieke zoekopdrachten:
#21 #23SELECT `id`
FROM `hmclx_menu`
WHERE `link` LIKE '%option=com_sppagebuilder&view=page&id=1%'
AND `published` = '1'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_menu | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 223 | Using where |
| Status | Duration |
|---|
| Starting | 0.07 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.03 ms |
| Optimizing | 0.02 ms |
| Statistics | 0.03 ms |
| Preparing | 0.03 ms |
| Executing | 0.00 ms |
| Sending data | 0.65 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.01 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 16 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 15 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/route.php:86 |
| 14 | SppagebuilderHelperRoute::getMenuItemId() | JROOT/components/com_sppagebuilder/helpers/route.php:65 |
| 13 | SppagebuilderHelperRoute::getFormRoute() | JROOT/components/com_sppagebuilder/models/page.php:90 |
| 12 | SppagebuilderModelPage->getItem() | JROOT/libraries/src/MVC/View/HtmlView.php:425 |
| 11 | Joomla\CMS\MVC\View\HtmlView->get() | JROOT/components/com_sppagebuilder/views/page/view.html.php:24 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 2.01 ms Na de laatste zoekopdracht: 0.10 ms Zoekopdracht geheugen: 0.024 MB geheugen voor zoekopdracht: 10.830 MB Regels teruggegeven: 48
Identieke zoekopdrachten:
#21 #22SELECT `id`
FROM `hmclx_menu`
WHERE `link` LIKE '%option=com_sppagebuilder&view=page&id=1%'
AND `published` = '1'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_menu | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 223 | Using where |
| Status | Duration |
|---|
| Starting | 0.06 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.02 ms |
| Statistics | 0.07 ms |
| Preparing | 0.02 ms |
| Executing | 0.01 ms |
| Sending data | 0.66 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 16 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 15 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/route.php:86 |
| 14 | SppagebuilderHelperRoute::getMenuItemId() | JROOT/components/com_sppagebuilder/helpers/route.php:67 |
| 13 | SppagebuilderHelperRoute::getFormRoute() | JROOT/components/com_sppagebuilder/models/page.php:90 |
| 12 | SppagebuilderModelPage->getItem() | JROOT/libraries/src/MVC/View/HtmlView.php:425 |
| 11 | Joomla\CMS\MVC\View\HtmlView->get() | JROOT/components/com_sppagebuilder/views/page/view.html.php:24 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.78 ms Na de laatste zoekopdracht: 0.46 ms Zoekopdracht geheugen: 0.033 MB geheugen voor zoekopdracht: 10.838 MB Regels teruggegeven: 106
SELECT `id`,`name`,`rules`,`parent_id`
FROM `hmclx_assets`
WHERE `name` LIKE 'com_sppagebuilder.%' OR `name` = 'com_sppagebuilder' OR `parent_id` = 0
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_assets | ALL | idx_asset_name,idx_parent_id | INDEX KEY ONTBREEKT | NULL | NULL | 288 | Using where |
| Status | Duration |
|---|
| Starting | 0.04 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.03 ms |
| Optimizing | 0.02 ms |
| Statistics | 0.12 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.30 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.04 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 17 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 16 | JDatabaseDriver->loadObjectList() | JROOT/libraries/src/Access/Access.php:359 |
| 15 | Joomla\CMS\Access\Access::preloadPermissions() | JROOT/libraries/src/Access/Access.php:226 |
| 14 | Joomla\CMS\Access\Access::preload() | JROOT/libraries/src/Access/Access.php:540 |
| 13 | Joomla\CMS\Access\Access::getAssetRules() | JROOT/libraries/src/Access/Access.php:183 |
| 12 | Joomla\CMS\Access\Access::check() | JROOT/libraries/src/User/User.php:398 |
| 11 | Joomla\CMS\User\User->authorise() | JROOT/components/com_sppagebuilder/views/page/view.html.php:26 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.44 ms Na de laatste zoekopdracht: 2.42 ms Zoekopdracht geheugen: 0.024 MB geheugen voor zoekopdracht: 10.988 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.06 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.09 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.06 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 17 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 16 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 15 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 14 | SppagebuilderHelperSite::addStylesheet() | JROOT/components/com_sppagebuilder/views/page/tmpl/default.php:26 |
| 13 | include JROOT/components/com_sppagebuilder/views/page/tmpl/default.php | JROOT/libraries/src/MVC/View/HtmlView.php:701 |
| 12 | Joomla\CMS\MVC\View\HtmlView->loadTemplate() | JROOT/libraries/src/MVC/View/HtmlView.php:230 |
| 11 | Joomla\CMS\MVC\View\HtmlView->display() | JROOT/components/com_sppagebuilder/views/page/view.html.php:43 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.29 ms Na de laatste zoekopdracht: 0.14 ms Zoekopdracht geheugen: 0.024 MB geheugen voor zoekopdracht: 10.997 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.03 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.01 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.01 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.04 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.02 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 17 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 16 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 15 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 14 | SppagebuilderHelperSite::addStylesheet() | JROOT/components/com_sppagebuilder/views/page/tmpl/default.php:27 |
| 13 | include JROOT/components/com_sppagebuilder/views/page/tmpl/default.php | JROOT/libraries/src/MVC/View/HtmlView.php:701 |
| 12 | Joomla\CMS\MVC\View\HtmlView->loadTemplate() | JROOT/libraries/src/MVC/View/HtmlView.php:230 |
| 11 | Joomla\CMS\MVC\View\HtmlView->display() | JROOT/components/com_sppagebuilder/views/page/view.html.php:43 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.40 ms Na de laatste zoekopdracht: 0.11 ms Zoekopdracht geheugen: 0.024 MB geheugen voor zoekopdracht: 11.006 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.03 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.01 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.01 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.04 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.03 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.00 ms |
| Query end | 0.01 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.10 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 17 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 16 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 15 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 14 | SppagebuilderHelperSite::addStylesheet() | JROOT/components/com_sppagebuilder/views/page/tmpl/default.php:32 |
| 13 | include JROOT/components/com_sppagebuilder/views/page/tmpl/default.php | JROOT/libraries/src/MVC/View/HtmlView.php:701 |
| 12 | Joomla\CMS\MVC\View\HtmlView->loadTemplate() | JROOT/libraries/src/MVC/View/HtmlView.php:230 |
| 11 | Joomla\CMS\MVC\View\HtmlView->display() | JROOT/components/com_sppagebuilder/views/page/view.html.php:43 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.27 ms Na de laatste zoekopdracht: 0.10 ms Zoekopdracht geheugen: 0.024 MB geheugen voor zoekopdracht: 11.015 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.02 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.01 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.01 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.04 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.02 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 17 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 16 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 15 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 14 | SppagebuilderHelperSite::addStylesheet() | JROOT/components/com_sppagebuilder/views/page/tmpl/default.php:37 |
| 13 | include JROOT/components/com_sppagebuilder/views/page/tmpl/default.php | JROOT/libraries/src/MVC/View/HtmlView.php:701 |
| 12 | Joomla\CMS\MVC\View\HtmlView->loadTemplate() | JROOT/libraries/src/MVC/View/HtmlView.php:230 |
| 11 | Joomla\CMS\MVC\View\HtmlView->display() | JROOT/components/com_sppagebuilder/views/page/view.html.php:43 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.34 ms Na de laatste zoekopdracht: 0.19 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 11.025 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.04 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.04 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.02 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 16 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 15 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 14 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/views/page/tmpl/default.php:41 |
| 13 | include JROOT/components/com_sppagebuilder/views/page/tmpl/default.php | JROOT/libraries/src/MVC/View/HtmlView.php:701 |
| 12 | Joomla\CMS\MVC\View\HtmlView->loadTemplate() | JROOT/libraries/src/MVC/View/HtmlView.php:230 |
| 11 | Joomla\CMS\MVC\View\HtmlView->display() | JROOT/components/com_sppagebuilder/views/page/view.html.php:43 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.31 ms Na de laatste zoekopdracht: 0.71 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 11.033 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.03 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.01 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.05 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.03 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 16 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 15 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 14 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/views/page/tmpl/default.php:42 |
| 13 | include JROOT/components/com_sppagebuilder/views/page/tmpl/default.php | JROOT/libraries/src/MVC/View/HtmlView.php:701 |
| 12 | Joomla\CMS\MVC\View\HtmlView->loadTemplate() | JROOT/libraries/src/MVC/View/HtmlView.php:230 |
| 11 | Joomla\CMS\MVC\View\HtmlView->display() | JROOT/components/com_sppagebuilder/views/page/view.html.php:43 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.42 ms Na de laatste zoekopdracht: 6.97 ms Zoekopdracht geheugen: 0.025 MB geheugen voor zoekopdracht: 11.288 MB Regels teruggegeven: 1
SELECT `template`
FROM `hmclx_template_styles`
WHERE `client_id` = 0
AND `home` = 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_template_styles | ALL | idx_client_id,idx_client_id_home | INDEX KEY ONTBREEKT | NULL | NULL | 13 | Using where |
| Status | Duration |
|---|
| Starting | 0.17 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.07 ms |
| After opening tables | 0.02 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.11 ms |
| Optimizing | 0.06 ms |
| Statistics | 0.17 ms |
| Preparing | 0.05 ms |
| Executing | 0.00 ms |
| Sending data | 0.08 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.04 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 18 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1662 |
| 17 | JDatabaseDriver->loadObject() | JROOT/components/com_sppagebuilder/parser/addon-parser.php:669 |
| 16 | AddonParser::getTemplateName() | JROOT/components/com_sppagebuilder/parser/addon-parser.php:159 |
| 15 | AddonParser::getAddons() | JROOT/components/com_sppagebuilder/parser/addon-parser.php:765 |
| 14 | require_once JROOT/components/com_sppagebuilder/parser/addon-parser.php | JROOT/components/com_sppagebuilder/views/page/tmpl/default.php:59 |
| 13 | include JROOT/components/com_sppagebuilder/views/page/tmpl/default.php | JROOT/libraries/src/MVC/View/HtmlView.php:701 |
| 12 | Joomla\CMS\MVC\View\HtmlView->loadTemplate() | JROOT/libraries/src/MVC/View/HtmlView.php:230 |
| 11 | Joomla\CMS\MVC\View\HtmlView->display() | JROOT/components/com_sppagebuilder/views/page/view.html.php:43 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 2.44 ms Na de laatste zoekopdracht: 89.50 ms Zoekopdracht geheugen: 0.025 MB geheugen voor zoekopdracht: 15.992 MB Regels teruggegeven: 1
SELECT `template`
FROM `hmclx_template_styles`
WHERE `client_id` = 0
AND `home` = 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_template_styles | ALL | idx_client_id,idx_client_id_home | INDEX KEY ONTBREEKT | NULL | NULL | 13 | Using where |
| Status | Duration |
|---|
| Starting | 0.17 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.06 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.02 ms |
| init | 0.11 ms |
| Optimizing | 0.07 ms |
| Statistics | 0.19 ms |
| Preparing | 0.05 ms |
| Executing | 0.01 ms |
| Sending data | 0.12 ms |
| End of update loop | 0.03 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 1.16 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 18 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1662 |
| 17 | JDatabaseDriver->loadObject() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:37 |
| 16 | SpPgaeBuilderBase::getTemplateName() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:45 |
| 15 | SpPgaeBuilderBase::loadAddons() | JROOT/components/com_sppagebuilder/parser/addon-parser.php:204 |
| 14 | AddonParser::viewAddons() | JROOT/components/com_sppagebuilder/views/page/tmpl/default.php:91 |
| 13 | include JROOT/components/com_sppagebuilder/views/page/tmpl/default.php | JROOT/libraries/src/MVC/View/HtmlView.php:701 |
| 12 | Joomla\CMS\MVC\View\HtmlView->loadTemplate() | JROOT/libraries/src/MVC/View/HtmlView.php:230 |
| 11 | Joomla\CMS\MVC\View\HtmlView->display() | JROOT/components/com_sppagebuilder/views/page/view.html.php:43 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 5.50 ms Na de laatste zoekopdracht: 19.56 ms Zoekopdracht geheugen: 0.027 MB geheugen voor zoekopdracht: 16.452 MB Regels teruggegeven: 0
SELECT a.enabled
FROM `hmclx_extensions` AS `a`
WHERE `a`.`name` = 'com_k2'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | a | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 270 | Using where |
| Status | Duration |
|---|
| Starting | 0.17 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.07 ms |
| After opening tables | 0.02 ms |
| System lock | 0.01 ms |
| table lock | 0.03 ms |
| init | 0.09 ms |
| Optimizing | 0.04 ms |
| Statistics | 0.08 ms |
| Preparing | 0.05 ms |
| Executing | 0.01 ms |
| Sending data | 0.74 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.02 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.01 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.40 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 19 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 18 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:545 |
| 17 | SpPgaeBuilderBase::k2CatList() | JROOT/components/com_sppagebuilder/addons/articles_scroller/admin.php:138 |
| 16 | require_once JROOT/components/com_sppagebuilder/addons/articles_scroller/admin.php | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:68 |
| 15 | SpPgaeBuilderBase::loadAddons() | JROOT/components/com_sppagebuilder/parser/addon-parser.php:204 |
| 14 | AddonParser::viewAddons() | JROOT/components/com_sppagebuilder/views/page/tmpl/default.php:91 |
| 13 | include JROOT/components/com_sppagebuilder/views/page/tmpl/default.php | JROOT/libraries/src/MVC/View/HtmlView.php:701 |
| 12 | Joomla\CMS\MVC\View\HtmlView->loadTemplate() | JROOT/libraries/src/MVC/View/HtmlView.php:230 |
| 11 | Joomla\CMS\MVC\View\HtmlView->display() | JROOT/components/com_sppagebuilder/views/page/view.html.php:43 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 2.55 ms Na de laatste zoekopdracht: 38.25 ms Zoekopdracht geheugen: 0.025 MB geheugen voor zoekopdracht: 18.533 MB Regels teruggegeven: 1
SELECT a.enabled
FROM `hmclx_extensions` AS `a`
WHERE (`a`.`element` = 'com_acymailing' OR `a`.`element` = 'com_acym')
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | a | range | element_clientid,element_folder_clientid | element_clientid | 402 | NULL | 2 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.20 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.06 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.12 ms |
| Optimizing | 0.06 ms |
| Statistics | 0.25 ms |
| Preparing | 0.05 ms |
| Executing | 0.01 ms |
| Sending data | 0.15 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.02 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.18 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 19 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 18 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:470 |
| 17 | SpPgaeBuilderBase::acymailingList() | JROOT/components/com_sppagebuilder/addons/optin_form/admin.php:163 |
| 16 | require_once JROOT/components/com_sppagebuilder/addons/optin_form/admin.php | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:68 |
| 15 | SpPgaeBuilderBase::loadAddons() | JROOT/components/com_sppagebuilder/parser/addon-parser.php:204 |
| 14 | AddonParser::viewAddons() | JROOT/components/com_sppagebuilder/views/page/tmpl/default.php:91 |
| 13 | include JROOT/components/com_sppagebuilder/views/page/tmpl/default.php | JROOT/libraries/src/MVC/View/HtmlView.php:701 |
| 12 | Joomla\CMS\MVC\View\HtmlView->loadTemplate() | JROOT/libraries/src/MVC/View/HtmlView.php:230 |
| 11 | Joomla\CMS\MVC\View\HtmlView->display() | JROOT/components/com_sppagebuilder/views/page/view.html.php:43 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.41 ms Na de laatste zoekopdracht: 0.19 ms Zoekopdracht geheugen: 0.026 MB geheugen voor zoekopdracht: 18.544 MB Regels teruggegeven: 1
SELECT `e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE e.element = 'com_acymailing' OR e.element = 'com_acym'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | range | element_clientid,element_folder_clientid | element_clientid | 402 | NULL | 2 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.05 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.07 ms |
| Preparing | 0.03 ms |
| Executing | 0.00 ms |
| Sending data | 0.05 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 20 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 19 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:529 |
| 18 | SpPgaeBuilderBase::getExtensionVersion() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:475 |
| 17 | SpPgaeBuilderBase::acymailingList() | JROOT/components/com_sppagebuilder/addons/optin_form/admin.php:163 |
| 16 | require_once JROOT/components/com_sppagebuilder/addons/optin_form/admin.php | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:68 |
| 15 | SpPgaeBuilderBase::loadAddons() | JROOT/components/com_sppagebuilder/parser/addon-parser.php:204 |
| 14 | AddonParser::viewAddons() | JROOT/components/com_sppagebuilder/views/page/tmpl/default.php:91 |
| 13 | include JROOT/components/com_sppagebuilder/views/page/tmpl/default.php | JROOT/libraries/src/MVC/View/HtmlView.php:701 |
| 12 | Joomla\CMS\MVC\View\HtmlView->loadTemplate() | JROOT/libraries/src/MVC/View/HtmlView.php:230 |
| 11 | Joomla\CMS\MVC\View\HtmlView->display() | JROOT/components/com_sppagebuilder/views/page/view.html.php:43 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.83 ms Na de laatste zoekopdracht: 0.12 ms Zoekopdracht geheugen: 0.025 MB geheugen voor zoekopdracht: 18.555 MB Regels teruggegeven: 1
SELECT `listid`,`name`
FROM `hmclx_acymailing_list`
WHERE `published` = '1'
ORDER BY name DESC
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_acymailing_list | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 1 | Using where; Gebruikt bestandssortering |
| Status | Duration |
|---|
| Starting | 0.05 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.02 ms |
| Preparing | 0.01 ms |
| Sorting result | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.01 ms |
| Creating sort index | 0.06 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.32 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 19 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 18 | JDatabaseDriver->loadObjectList() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:492 |
| 17 | SpPgaeBuilderBase::acymailingList() | JROOT/components/com_sppagebuilder/addons/optin_form/admin.php:163 |
| 16 | require_once JROOT/components/com_sppagebuilder/addons/optin_form/admin.php | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:68 |
| 15 | SpPgaeBuilderBase::loadAddons() | JROOT/components/com_sppagebuilder/parser/addon-parser.php:204 |
| 14 | AddonParser::viewAddons() | JROOT/components/com_sppagebuilder/views/page/tmpl/default.php:91 |
| 13 | include JROOT/components/com_sppagebuilder/views/page/tmpl/default.php | JROOT/libraries/src/MVC/View/HtmlView.php:701 |
| 12 | Joomla\CMS\MVC\View\HtmlView->loadTemplate() | JROOT/libraries/src/MVC/View/HtmlView.php:230 |
| 11 | Joomla\CMS\MVC\View\HtmlView->display() | JROOT/components/com_sppagebuilder/views/page/view.html.php:43 |
| 10 | SppagebuilderViewPage->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:664 |
| 9 | Joomla\CMS\MVC\Controller\BaseController->display() | JROOT/components/com_sppagebuilder/controller.php:68 |
| 8 | SppagebuilderController->display() | JROOT/libraries/src/MVC/Controller/BaseController.php:702 |
| 7 | Joomla\CMS\MVC\Controller\BaseController->execute() | JROOT/components/com_sppagebuilder/sppagebuilder.php:23 |
| 6 | require_once JROOT/components/com_sppagebuilder/sppagebuilder.php | JROOT/libraries/src/Component/ComponentHelper.php:402 |
| 5 | Joomla\CMS\Component\ComponentHelper::executeComponent() | JROOT/libraries/src/Component/ComponentHelper.php:377 |
| 4 | Joomla\CMS\Component\ComponentHelper::renderComponent() | JROOT/libraries/src/Application/SiteApplication.php:194 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.36 ms Na de laatste zoekopdracht: 91.72 ms Zoekopdracht geheugen: 0.021 MB geheugen voor zoekopdracht: 19.529 MB Regels teruggegeven: 4
SELECT language,id
FROM `hmclx_menu`
WHERE home = 1
AND published = 1
AND client_id = 0
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_menu | ALL | idx_client_id_parent_id_alias_language | INDEX KEY ONTBREEKT | NULL | NULL | 223 | Using where |
| Status | Duration |
|---|
| Starting | 0.19 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.06 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.08 ms |
| Optimizing | 0.04 ms |
| Statistics | 0.12 ms |
| Preparing | 0.12 ms |
| Executing | 0.01 ms |
| Sending data | 0.34 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.05 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 10 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 9 | JDatabaseDriver->loadObjectList() | JROOT/libraries/src/Language/Multilanguage.php:107 |
| 8 | Joomla\CMS\Language\Multilanguage::getSiteHomePages() | JROOT/plugins/system/languagefilter/languagefilter.php:751 |
| 7 | PlgSystemLanguageFilter->onAfterDispatch() | JROOT/libraries/joomla/event/event.php:70 |
| 6 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 5 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 4 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/SiteApplication.php:199 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.87 ms Na de laatste zoekopdracht: 2.71 ms Zoekopdracht geheugen: 0.021 MB geheugen voor zoekopdracht: 19.606 MB Regels teruggegeven: 0
SELECT `c2`.`language`,`c2`.`id`
FROM `hmclx_menu` AS `c`
INNER JOIN `hmclx_associations` AS `a`
ON a.id = c.`id`
AND a.context='com_menus.item'
INNER JOIN `hmclx_associations` AS `a2`
ON `a`.`key` = `a2`.`key`
INNER JOIN `hmclx_menu` AS `c2`
ON a2.id = c2.`id`
WHERE c.id = 437
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | NULL | NULL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | NULL | Impossible WHERE noticed after reading const tables |
| Status | Duration |
|---|
| Starting | 0.15 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.08 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.04 ms |
| Optimizing | 0.05 ms |
| Statistics | 0.14 ms |
| Preparing | 0.01 ms |
| Executing | 0.01 ms |
| End of update loop | 0.00 ms |
| Query end | 0.01 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.09 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 11 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 10 | JDatabaseDriver->loadObjectList() | JROOT/libraries/src/Language/Associations.php:115 |
| 9 | Joomla\CMS\Language\Associations::getAssociations() | JROOT/administrator/components/com_menus/helpers/menus.php:321 |
| 8 | MenusHelper::getAssociations() | JROOT/plugins/system/languagefilter/languagefilter.php:768 |
| 7 | PlgSystemLanguageFilter->onAfterDispatch() | JROOT/libraries/joomla/event/event.php:70 |
| 6 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 5 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 4 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/SiteApplication.php:199 |
| 3 | Joomla\CMS\Application\SiteApplication->dispatch() | JROOT/libraries/src/Application/SiteApplication.php:233 |
| 2 | Joomla\CMS\Application\SiteApplication->doExecute() | JROOT/libraries/src/Application/CMSApplication.php:225 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 2.08 ms Na de laatste zoekopdracht: 250.25 ms Zoekopdracht geheugen: 0.026 MB geheugen voor zoekopdracht: 20.794 MB Regels teruggegeven: 15
SELECT m.id, m.title, m.module, m.position, m.content, m.showtitle, m.params, mm.menuid
FROM hmclx_modules AS m
LEFT JOIN hmclx_modules_menu AS mm
ON mm.moduleid = m.id
LEFT JOIN hmclx_extensions AS e
ON e.element = m.module
AND e.client_id = m.client_id
WHERE m.published = 1
AND e.enabled = 1
AND (m.publish_up = '0000-00-00 00:00:00' OR m.publish_up <= '2026-08-01 20:21:03')
AND (m.publish_down = '0000-00-00 00:00:00' OR m.publish_down >= '2026-08-01 20:21:03')
AND m.access IN (1,1,7)
AND m.client_id = 0
AND (mm.menuid = 437 OR mm.menuid <= 0)
AND m.language IN ('nl-NL','*')
ORDER BY m.position, m.ordering
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | m | ref | PRIMARY,published,newsfeeds,idx_language | published | 1 | const | 29 | Using index condition; Using where; Gebruikt bestandssortering |
| 1 | SIMPLE | mm | ref | PRIMARY | PRIMARY | 4 | dblbefit_live.m.id | 1 | Using where; Using index |
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 403 | dblbefit_live.m.module,const | 1 | Using index condition; Using where |
| Status | Duration |
|---|
| Starting | 0.28 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.07 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.16 ms |
| Optimizing | 0.10 ms |
| Statistics | 0.28 ms |
| Preparing | 0.09 ms |
| Sorting result | 0.02 ms |
| Executing | 0.01 ms |
| Sending data | 0.02 ms |
| Creating sort index | 0.59 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.03 ms |
| Updating status | 0.04 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 18 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 17 | JDatabaseDriver->loadObjectList() | Zelfde als de call in onderstaande regel. |
| 16 | call_user_func_array() | JROOT/libraries/src/Cache/Controller/CallbackController.php:173 |
| 15 | Joomla\CMS\Cache\Controller\CallbackController->get() | JROOT/libraries/src/Helper/ModuleHelper.php:441 |
| 14 | Joomla\CMS\Helper\ModuleHelper::getModuleList() | JROOT/libraries/src/Helper/ModuleHelper.php:371 |
| 13 | Joomla\CMS\Helper\ModuleHelper::load() | JROOT/libraries/src/Helper/ModuleHelper.php:87 |
| 12 | Joomla\CMS\Helper\ModuleHelper::getModules() | JROOT/libraries/src/Document/HtmlDocument.php:601 |
| 11 | Joomla\CMS\Document\HtmlDocument->countModules() | JROOT/plugins/system/helix3/core/helix3.php:542 |
| 10 | Helix3::countModules() | JROOT/plugins/system/helix3/core/helix3.php:500 |
| 9 | Helix3::rowColumns() | JROOT/plugins/system/helix3/core/helix3.php:316 |
| 8 | Helix3::generatelayout() | JROOT/templates/shaper_floox/index.php:193 |
| 7 | require JROOT/templates/shaper_floox/index.php | JROOT/libraries/src/Document/HtmlDocument.php:678 |
| 6 | Joomla\CMS\Document\HtmlDocument->_loadTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:740 |
| 5 | Joomla\CMS\Document\HtmlDocument->_fetchTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:555 |
| 4 | Joomla\CMS\Document\HtmlDocument->parse() | JROOT/libraries/src/Application/CMSApplication.php:1098 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 3.11 ms Na de laatste zoekopdracht: 50.44 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 20.916 MB Regels teruggegeven: 1
SELECT *
FROM `hmclx_sppagebuilder`
WHERE `extension` = 'mod_sppagebuilder'
AND `extension_view` = 'module'
AND `view_id` = '119'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_sppagebuilder | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 138 | Using where |
| Status | Duration |
|---|
| Starting | 0.31 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.20 ms |
| After opening tables | 0.02 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.14 ms |
| Optimizing | 0.06 ms |
| Statistics | 0.07 ms |
| Preparing | 0.09 ms |
| Executing | 0.01 ms |
| Sending data | 1.73 ms |
| End of update loop | 0.02 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.02 ms |
| Starting cleanup | 0.01 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.05 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 14 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1662 |
| 13 | JDatabaseDriver->loadObject() | JROOT/modules/mod_sppagebuilder/helper.php:38 |
| 12 | ModSPagebuilderHelper::pageBuilderData() | JROOT/modules/mod_sppagebuilder/helper.php:14 |
| 11 | ModSPagebuilderHelper::getData() | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:13 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.90 ms Na de laatste zoekopdracht: 1.36 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 20.934 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.13 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.04 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.04 ms |
| Optimizing | 0.02 ms |
| Statistics | 0.19 ms |
| Preparing | 0.03 ms |
| Executing | 0.00 ms |
| Sending data | 0.13 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.05 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:22 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.44 ms Na de laatste zoekopdracht: 0.30 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 20.942 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.07 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.07 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.04 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:23 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.38 ms Na de laatste zoekopdracht: 0.21 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 20.949 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.06 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.05 ms |
| Preparing | 0.02 ms |
| Executing | 0.01 ms |
| Sending data | 0.05 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:28 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.27 ms Na de laatste zoekopdracht: 0.13 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 20.956 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.03 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.01 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.01 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.04 ms |
| Preparing | 0.01 ms |
| Executing | 0.01 ms |
| Sending data | 0.03 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:33 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.27 ms Na de laatste zoekopdracht: 0.15 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 20.963 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.03 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.01 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.01 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.04 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.02 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 14 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 13 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 12 | SppagebuilderHelperSite::getVersion() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:37 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.29 ms Na de laatste zoekopdracht: 0.87 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 20.970 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.04 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.01 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.01 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.04 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.03 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 14 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 13 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 12 | SppagebuilderHelperSite::getVersion() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:38 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.37 ms Na de laatste zoekopdracht: 1.05 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 20.989 MB Regels teruggegeven: 1
SELECT `template`
FROM `hmclx_template_styles`
WHERE `client_id` = 0
AND `home` = 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_template_styles | ALL | idx_client_id,idx_client_id_home | INDEX KEY ONTBREEKT | NULL | NULL | 13 | Using where |
| Status | Duration |
|---|
| Starting | 0.04 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.03 ms |
| Optimizing | 0.03 ms |
| Statistics | 0.05 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.05 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 16 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1662 |
| 15 | JDatabaseDriver->loadObject() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:37 |
| 14 | SpPgaeBuilderBase::getTemplateName() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:45 |
| 13 | SpPgaeBuilderBase::loadAddons() | JROOT/components/com_sppagebuilder/parser/addon-parser.php:204 |
| 12 | AddonParser::viewAddons() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:42 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 2.72 ms Na de laatste zoekopdracht: 39.96 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 20.979 MB Regels teruggegeven: 1
SELECT *
FROM `hmclx_sppagebuilder`
WHERE `extension` = 'mod_sppagebuilder'
AND `extension_view` = 'module'
AND `view_id` = '113'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_sppagebuilder | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 138 | Using where |
| Status | Duration |
|---|
| Starting | 0.16 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.07 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.03 ms |
| init | 0.17 ms |
| Optimizing | 0.06 ms |
| Statistics | 0.07 ms |
| Preparing | 0.05 ms |
| Executing | 0.01 ms |
| Sending data | 1.66 ms |
| End of update loop | 0.02 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.05 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 14 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1662 |
| 13 | JDatabaseDriver->loadObject() | JROOT/modules/mod_sppagebuilder/helper.php:38 |
| 12 | ModSPagebuilderHelper::pageBuilderData() | JROOT/modules/mod_sppagebuilder/helper.php:14 |
| 11 | ModSPagebuilderHelper::getData() | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:13 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.74 ms Na de laatste zoekopdracht: 1.35 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.003 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.12 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.04 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.04 ms |
| Optimizing | 0.02 ms |
| Statistics | 0.17 ms |
| Preparing | 0.03 ms |
| Executing | 0.00 ms |
| Sending data | 0.09 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.01 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:22 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.41 ms Na de laatste zoekopdracht: 0.24 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.010 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.07 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.07 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.04 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:23 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.35 ms Na de laatste zoekopdracht: 0.21 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.017 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.07 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.05 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.03 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:28 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.32 ms Na de laatste zoekopdracht: 0.17 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.024 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.05 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.05 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.03 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:33 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.33 ms Na de laatste zoekopdracht: 0.17 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.032 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.04 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.01 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.05 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.03 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 14 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 13 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 12 | SppagebuilderHelperSite::getVersion() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:37 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.35 ms Na de laatste zoekopdracht: 1.15 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.038 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.05 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.01 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.05 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.03 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 14 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 13 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 12 | SppagebuilderHelperSite::getVersion() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:38 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.40 ms Na de laatste zoekopdracht: 1.03 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.071 MB Regels teruggegeven: 1
SELECT `template`
FROM `hmclx_template_styles`
WHERE `client_id` = 0
AND `home` = 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_template_styles | ALL | idx_client_id,idx_client_id_home | INDEX KEY ONTBREEKT | NULL | NULL | 13 | Using where |
| Status | Duration |
|---|
| Starting | 0.04 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.03 ms |
| Optimizing | 0.03 ms |
| Statistics | 0.06 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.05 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 16 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1662 |
| 15 | JDatabaseDriver->loadObject() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:37 |
| 14 | SpPgaeBuilderBase::getTemplateName() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:45 |
| 13 | SpPgaeBuilderBase::loadAddons() | JROOT/components/com_sppagebuilder/parser/addon-parser.php:204 |
| 12 | AddonParser::viewAddons() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:42 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 3.28 ms Na de laatste zoekopdracht: 35.38 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.042 MB Regels teruggegeven: 1
SELECT *
FROM `hmclx_sppagebuilder`
WHERE `extension` = 'mod_sppagebuilder'
AND `extension_view` = 'module'
AND `view_id` = '134'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_sppagebuilder | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 138 | Using where |
| Status | Duration |
|---|
| Starting | 0.20 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.07 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.15 ms |
| Optimizing | 0.07 ms |
| Statistics | 0.07 ms |
| Preparing | 0.06 ms |
| Executing | 0.01 ms |
| Sending data | 2.12 ms |
| End of update loop | 0.02 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.06 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 14 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1662 |
| 13 | JDatabaseDriver->loadObject() | JROOT/modules/mod_sppagebuilder/helper.php:38 |
| 12 | ModSPagebuilderHelper::pageBuilderData() | JROOT/modules/mod_sppagebuilder/helper.php:14 |
| 11 | ModSPagebuilderHelper::getData() | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:13 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.77 ms Na de laatste zoekopdracht: 1.20 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.065 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.13 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.04 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.04 ms |
| Optimizing | 0.02 ms |
| Statistics | 0.17 ms |
| Preparing | 0.03 ms |
| Executing | 0.00 ms |
| Sending data | 0.09 ms |
| End of update loop | 0.00 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.01 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:22 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.57 ms Na de laatste zoekopdracht: 0.27 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.073 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.11 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.03 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.12 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.05 ms |
| End of update loop | 0.00 ms |
| Query end | 0.01 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:23 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.45 ms Na de laatste zoekopdracht: 0.23 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.080 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.10 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.06 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.04 ms |
| End of update loop | 0.00 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:28 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.34 ms Na de laatste zoekopdracht: 0.17 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.087 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.05 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.05 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.03 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:33 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.29 ms Na de laatste zoekopdracht: 0.17 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.094 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.04 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.01 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.04 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.03 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 14 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 13 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 12 | SppagebuilderHelperSite::getVersion() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:37 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.31 ms Na de laatste zoekopdracht: 0.96 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.101 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.04 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.01 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.01 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.05 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.03 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 14 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 13 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 12 | SppagebuilderHelperSite::getVersion() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:38 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.44 ms Na de laatste zoekopdracht: 1.19 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.137 MB Regels teruggegeven: 1
SELECT `template`
FROM `hmclx_template_styles`
WHERE `client_id` = 0
AND `home` = 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_template_styles | ALL | idx_client_id,idx_client_id_home | INDEX KEY ONTBREEKT | NULL | NULL | 13 | Using where |
| Status | Duration |
|---|
| Starting | 0.05 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.03 ms |
| Optimizing | 0.03 ms |
| Statistics | 0.06 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.05 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 16 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1662 |
| 15 | JDatabaseDriver->loadObject() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:37 |
| 14 | SpPgaeBuilderBase::getTemplateName() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:45 |
| 13 | SpPgaeBuilderBase::loadAddons() | JROOT/components/com_sppagebuilder/parser/addon-parser.php:204 |
| 12 | AddonParser::viewAddons() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:42 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 3.09 ms Na de laatste zoekopdracht: 39.99 ms Zoekopdracht geheugen: 0.038 MB geheugen voor zoekopdracht: 21.104 MB Regels teruggegeven: 1
SELECT *
FROM `hmclx_sppagebuilder`
WHERE `extension` = 'mod_sppagebuilder'
AND `extension_view` = 'module'
AND `view_id` = '116'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_sppagebuilder | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 138 | Using where |
| Status | Duration |
|---|
| Starting | 0.19 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.10 ms |
| After opening tables | 0.02 ms |
| System lock | 0.01 ms |
| table lock | 0.03 ms |
| init | 0.16 ms |
| Optimizing | 0.08 ms |
| Statistics | 0.07 ms |
| Preparing | 0.07 ms |
| Executing | 0.01 ms |
| Sending data | 1.78 ms |
| End of update loop | 0.03 ms |
| Query end | 0.01 ms |
| Commit | 0.02 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.01 ms |
| closing tables | 0.02 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.01 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.07 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 14 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1662 |
| 13 | JDatabaseDriver->loadObject() | JROOT/modules/mod_sppagebuilder/helper.php:38 |
| 12 | ModSPagebuilderHelper::pageBuilderData() | JROOT/modules/mod_sppagebuilder/helper.php:14 |
| 11 | ModSPagebuilderHelper::getData() | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:13 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.96 ms Na de laatste zoekopdracht: 1.36 ms Zoekopdracht geheugen: 0.028 MB geheugen voor zoekopdracht: 21.140 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.15 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.12 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.02 ms |
| init | 0.05 ms |
| Optimizing | 0.03 ms |
| Statistics | 0.20 ms |
| Preparing | 0.04 ms |
| Executing | 0.00 ms |
| Sending data | 0.10 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:22 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.39 ms Na de laatste zoekopdracht: 0.20 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.153 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.06 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.06 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.04 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:23 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.41 ms Na de laatste zoekopdracht: 0.16 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.160 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.06 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.07 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.04 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:28 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.34 ms Na de laatste zoekopdracht: 0.16 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.168 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.04 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.01 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.04 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.03 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 14 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 13 | SppagebuilderHelperSite::getVersion() | JROOT/components/com_sppagebuilder/helpers/helper.php:120 |
| 12 | SppagebuilderHelperSite::addStylesheet() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:33 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.28 ms Na de laatste zoekopdracht: 0.25 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.175 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.04 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.01 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.04 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.02 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 14 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 13 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 12 | SppagebuilderHelperSite::getVersion() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:37 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.28 ms Na de laatste zoekopdracht: 0.81 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.182 MB Regels teruggegeven: 1
SELECT e.manifest_cache,`e`.`manifest_cache`
FROM `hmclx_extensions` AS `e`
WHERE `e`.`element` = 'com_sppagebuilder'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | e | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.04 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.04 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.02 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 14 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 13 | JDatabaseDriver->loadResult() | JROOT/components/com_sppagebuilder/helpers/helper.php:134 |
| 12 | SppagebuilderHelperSite::getVersion() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:38 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.48 ms Na de laatste zoekopdracht: 1.09 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.249 MB Regels teruggegeven: 1
SELECT `template`
FROM `hmclx_template_styles`
WHERE `client_id` = 0
AND `home` = 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_template_styles | ALL | idx_client_id,idx_client_id_home | INDEX KEY ONTBREEKT | NULL | NULL | 13 | Using where |
| Status | Duration |
|---|
| Starting | 0.05 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.04 ms |
| Optimizing | 0.03 ms |
| Statistics | 0.07 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.10 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 16 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1662 |
| 15 | JDatabaseDriver->loadObject() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:37 |
| 14 | SpPgaeBuilderBase::getTemplateName() | JROOT/administrator/components/com_sppagebuilder/builder/classes/base.php:45 |
| 13 | SpPgaeBuilderBase::loadAddons() | JROOT/components/com_sppagebuilder/parser/addon-parser.php:204 |
| 12 | AddonParser::viewAddons() | JROOT/modules/mod_sppagebuilder/tmpl/default.php:42 |
| 11 | require JROOT/modules/mod_sppagebuilder/tmpl/default.php | JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php:16 |
| 10 | include JROOT/modules/mod_sppagebuilder/mod_sppagebuilder.php | JROOT/libraries/src/Helper/ModuleHelper.php:200 |
| 9 | Joomla\CMS\Helper\ModuleHelper::renderModule() | JROOT/libraries/src/Document/Renderer/Html/ModuleRenderer.php:98 |
| 8 | Joomla\CMS\Document\Renderer\Html\ModuleRenderer->render() | JROOT/libraries/src/Document/Renderer/Html/ModulesRenderer.php:47 |
| 7 | Joomla\CMS\Document\Renderer\Html\ModulesRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.07 ms Na de laatste zoekopdracht: 66.13 ms Zoekopdracht geheugen: 0.023 MB geheugen voor zoekopdracht: 21.623 MB Regels teruggegeven: 0
SELECT id, url, title, lightboxUrl, form_id
FROM hmclx_bagallery_items
WHERE lightboxUrl = '/'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_bagallery_items | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 56 | Using where |
| Status | Duration |
|---|
| Starting | 0.18 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.06 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.08 ms |
| Optimizing | 0.03 ms |
| Statistics | 0.06 ms |
| Preparing | 0.04 ms |
| Executing | 0.01 ms |
| Sending data | 0.21 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 16 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 15 | JDatabaseDriver->loadObjectList() | JROOT/components/com_bagallery/helpers/bagallery.php:151 |
| 14 | bagalleryHelper::checkImage() | JROOT/components/com_bagallery/helpers/bagallery.php:34 |
| 13 | bagalleryHelper::addStyle() | JROOT/plugins/system/bagallery/bagallery.php:46 |
| 12 | plgSystemBagallery->onBeforeCompileHead() | JROOT/libraries/joomla/event/event.php:70 |
| 11 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 10 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 9 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Document/Renderer/Html/HeadRenderer.php:67 |
| 8 | Joomla\CMS\Document\Renderer\Html\HeadRenderer->fetchHead() | JROOT/libraries/src/Document/Renderer/Html/HeadRenderer.php:38 |
| 7 | Joomla\CMS\Document\Renderer\Html\HeadRenderer->render() | JROOT/libraries/src/Document/HtmlDocument.php:511 |
| 6 | Joomla\CMS\Document\HtmlDocument->getBuffer() | JROOT/libraries/src/Document/HtmlDocument.php:803 |
| 5 | Joomla\CMS\Document\HtmlDocument->_renderTemplate() | JROOT/libraries/src/Document/HtmlDocument.php:577 |
| 4 | Joomla\CMS\Document\HtmlDocument->render() | JROOT/libraries/src/Application/CMSApplication.php:1112 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.23 ms Na de laatste zoekopdracht: 33.57 ms Zoekopdracht geheugen: 0.027 MB geheugen voor zoekopdracht: 22.283 MB Regels teruggegeven: 86
SELECT *
FROM hmclx_acymailing_config
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_acymailing_config | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 86 | |
| Status | Duration |
|---|
| Starting | 0.16 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.07 ms |
| After opening tables | 0.02 ms |
| System lock | 0.01 ms |
| table lock | 0.03 ms |
| init | 0.07 ms |
| Optimizing | 0.02 ms |
| Statistics | 0.07 ms |
| Preparing | 0.05 ms |
| Executing | 0.01 ms |
| Sending data | 0.23 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.02 ms |
| Query end | 0.01 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.01 ms |
| closing tables | 0.01 ms |
| Query end | 0.02 ms |
| Starting cleanup | 0.01 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.04 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 15 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1701 |
| 14 | JDatabaseDriver->loadObjectList() | JROOT/administrator/components/com_acymailing/compat/joomla.php:481 |
| 13 | acymailing_loadObjectList() | JROOT/administrator/components/com_acymailing/classes/cpanel.php:17 |
| 12 | cpanelClass->load() | JROOT/administrator/components/com_acymailing/helpers/helper.php:438 |
| 11 | acymailing_config() | JROOT/administrator/components/com_acymailing/compat/joomla.php:822 |
| 10 | include_once JROOT/administrator/components/com_acymailing/compat/joomla.php | JROOT/administrator/components/com_acymailing/helpers/helper.php:22 |
| 9 | include_once JROOT/administrator/components/com_acymailing/helpers/helper.php | JROOT/plugins/system/regacymailing/regacymailing.php:22 |
| 8 | plgSystemRegacymailing->initAcy() | JROOT/plugins/system/regacymailing/regacymailing.php:146 |
| 7 | plgSystemRegacymailing->onAfterRender() | JROOT/libraries/joomla/event/event.php:70 |
| 6 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 5 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 4 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:1118 |
| 3 | Joomla\CMS\Application\CMSApplication->render() | JROOT/libraries/src/Application/SiteApplication.php:778 |
| 2 | Joomla\CMS\Application\SiteApplication->render() | JROOT/libraries/src/Application/CMSApplication.php:231 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 2.88 ms Na de laatste zoekopdracht: 151.83 ms Zoekopdracht geheugen: 0.161 MB geheugen voor zoekopdracht: 27.926 MB Regels teruggegeven: 1
SELECT `params`
FROM `hmclx_extensions`
WHERE `type` = 'component'
AND `element` = 'com_htprotect'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_extensions | ref | element_clientid,element_folder_clientid,extension | element_clientid | 402 | const | 1 | Using index condition; Using where |
| Status | Duration |
|---|
| Starting | 0.20 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.07 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.10 ms |
| Optimizing | 0.06 ms |
| Statistics | 0.26 ms |
| Preparing | 0.06 ms |
| Executing | 0.01 ms |
| Sending data | 0.33 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.02 ms |
| Query end | 0.01 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.02 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.01 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 9 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 8 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_htprotect/core/config.php:335 |
| 7 | HtpConfig::load() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3119 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 7.15 ms Na de laatste zoekopdracht: 6.67 ms Zoekopdracht geheugen: 0.005 MB geheugen voor zoekopdracht: 28.164 MB
UPDATE `hmclx_session`
SET `data` = 'joomla|s:840:\"TzoyNDoiSm9vbWxhXFJlZ2lzdHJ5XFJlZ2lzdHJ5IjozOntzOjc6IgAqAGRhdGEiO086ODoic3RkQ2xhc3MiOjE6e3M6OToiX19kZWZhdWx0IjtPOjg6InN0ZENsYXNzIjo0OntzOjc6InNlc3Npb24iO086ODoic3RkQ2xhc3MiOjM6e3M6NzoiY291bnRlciI7aToxO3M6NToidGltZXIiO086ODoic3RkQ2xhc3MiOjM6e3M6NToic3RhcnQiO2k6MTc4NTYxNTY2MztzOjQ6Imxhc3QiO2k6MTc4NTYxNTY2MztzOjM6Im5vdyI7aToxNzg1NjE1NjYzO31zOjU6InRva2VuIjtzOjMyOiJjQmdCMXplSWxpOTRmeGVQbDc3T05UYktybkxlYUlQZCI7fXM6ODoicmVnaXN0cnkiO086MjQ6Ikpvb21sYVxSZWdpc3RyeVxSZWdpc3RyeSI6Mzp7czo3OiIAKgBkYXRhIjtPOjg6InN0ZENsYXNzIjowOnt9czoxNDoiACoAaW5pdGlhbGl6ZWQiO2I6MDtzOjk6InNlcGFyYXRvciI7czoxOiIuIjt9czo0OiJ1c2VyIjtPOjIwOiJKb29tbGFcQ01TXFVzZXJcVXNlciI6MTp7czoyOiJpZCI7aTowO31zOjI1OiJwbGdfc3lzdGVtX2xhbmd1YWdlZmlsdGVyIjtPOjg6InN0ZENsYXNzIjoxOntzOjg6Imxhbmd1YWdlIjtzOjU6Im5sLU5MIjt9fX1zOjE0OiIAKgBpbml0aWFsaXplZCI7YjowO3M6OToic2VwYXJhdG9yIjtzOjE6Ii4iO30=\";'
, `time` = 1785615665
WHERE `session_id` = X'383539616c6d353261726c646539706e347470313639326b3430'
VERKLAREN niet mogelijk voor zoekopdracht: UPDATE `hmclx_session`
SET `data` = 'joomla|s:840:\"TzoyNDoiSm9vbWxhXFJlZ2lzdHJ5XFJlZ2lzdHJ5IjozOntzOjc6IgAqAGRhdGEiO086ODoic3RkQ2xhc3MiOjE6e3M6OToiX19kZWZhdWx0IjtPOjg6InN0ZENsYXNzIjo0OntzOjc6InNlc3Npb24iO086ODoic3RkQ2xhc3MiOjM6e3M6NzoiY291bnRlciI7aToxO3M6NToidGltZXIiO086ODoic3RkQ2xhc3MiOjM6e3M6NToic3RhcnQiO2k6MTc4NTYxNTY2MztzOjQ6Imxhc3QiO2k6MTc4NTYxNTY2MztzOjM6Im5vdyI7aToxNzg1NjE1NjYzO31zOjU6InRva2VuIjtzOjMyOiJjQmdCMXplSWxpOTRmeGVQbDc3T05UYktybkxlYUlQZCI7fXM6ODoicmVnaXN0cnkiO086MjQ6Ikpvb21sYVxSZWdpc3RyeVxSZWdpc3RyeSI6Mzp7czo3OiIAKgBkYXRhIjtPOjg6InN0ZENsYXNzIjowOnt9czoxNDoiACoAaW5pdGlhbGl6ZWQiO2I6MDtzOjk6InNlcGFyYXRvciI7czoxOiIuIjt9czo0OiJ1c2VyIjtPOjIwOiJKb29tbGFcQ01TXFVzZXJcVXNlciI6MTp7czoyOiJpZCI7aTowO31zOjI1OiJwbGdfc3lzdGVtX2xhbmd1YWdlZmlsdGVyIjtPOjg6InN0ZENsYXNzIjoxOntzOjg6Imxhbmd1YWdlIjtzOjU6Im5sLU5MIjt9fX1zOjE0OiIAKgBpbml0aWFsaXplZCI7YjowO3M6OToic2VwYXJhdG9yIjtzOjE6Ii4iO30=\";'
, `time` = 1785615665
WHERE `session_id` = X'383539616c6d353261726c646539706e347470313639326b3430'
| Status | Duration |
|---|
| Starting | 0.45 ms |
| checking permissions | 0.03 ms |
| Opening tables | 0.09 ms |
| After opening tables | 0.02 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init for update | 0.22 ms |
| Updating | 0.33 ms |
| End of update loop | 0.01 ms |
| Waiting for query cache lock | 0.00 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 5.65 ms |
| Query end | 0.02 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.01 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.01 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.84 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 12 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/session/storage/database.php:84 |
| 11 | JSessionStorageDatabase->write() | Zelfde als de call in onderstaande regel. |
| 10 | session_write_close() | JROOT/libraries/joomla/session/handler/native.php:194 |
| 9 | JSessionHandlerNative->save() | JROOT/libraries/src/Session/Session.php:824 |
| 8 | Joomla\CMS\Session\Session->close() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3445 |
| 7 | PlgSystemHtprotectwatch->backgroundDetach() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3127 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.26 ms Na de laatste zoekopdracht: 0.69 ms Zoekopdracht geheugen: 0.161 MB geheugen voor zoekopdracht: 28.168 MB Regels teruggegeven: 1
SELECT `params`
FROM `hmclx_extensions`
WHERE `type` = 'component'
AND `element` = 'com_htprotect'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_extensions | ref | element_clientid,element_folder_clientid,extension | element_clientid | 402 | const | 1 | Using index condition; Using where |
| Status | Duration |
|---|
| Starting | 0.13 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.05 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.07 ms |
| Optimizing | 0.05 ms |
| Statistics | 0.20 ms |
| Preparing | 0.06 ms |
| Executing | 0.01 ms |
| Sending data | 0.47 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.05 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 1.87 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 11 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 10 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_htprotect/core/config.php:335 |
| 9 | HtpConfig::load() | JROOT/administrator/components/com_htprotect/core/compat_guard.php:1271 |
| 8 | HtpCompat::enabledByConfig() | JROOT/administrator/components/com_htprotect/core/compat_guard.php:184 |
| 7 | HtpCompat::observeState() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3141 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.75 ms Na de laatste zoekopdracht: 2.93 ms Zoekopdracht geheugen: 0.021 MB geheugen voor zoekopdracht: 28.165 MB Regels teruggegeven: 1
SELECT COUNT(*)
FROM `hmclx_extensions`
WHERE `type` = 'plugin'
AND `folder` = 'behaviour'
AND `element` IN ('compat', 'compat6')
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_extensions | range | element_clientid,element_folder_clientid,extension | extension | 886 | NULL | 2 | Using where; Using index |
| Status | Duration |
|---|
| Starting | 0.12 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.05 ms |
| Optimizing | 0.03 ms |
| Statistics | 0.14 ms |
| Preparing | 0.03 ms |
| Executing | 0.00 ms |
| Sending data | 0.06 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 1.03 ms |
| Query end | 0.03 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 11 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 10 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_htprotect/core/compat_guard.php:1316 |
| 9 | HtpCompat::scalar() | JROOT/administrator/components/com_htprotect/core/compat_guard.php:1328 |
| 8 | HtpCompat::bcExists() | JROOT/administrator/components/com_htprotect/core/compat_guard.php:200 |
| 7 | HtpCompat::observeState() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3141 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.07 ms Na de laatste zoekopdracht: 1.04 ms Zoekopdracht geheugen: 0.021 MB geheugen voor zoekopdracht: 28.170 MB Regels teruggegeven: 1
Identieke zoekopdrachten:
#86SELECT `rules`
FROM `hmclx_assets`
WHERE `id` = 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_assets | const | PRIMARY | PRIMARY | 4 | const | 1 | |
| Status | Duration |
|---|
| Starting | 0.07 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.04 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.03 ms |
| Optimizing | 0.02 ms |
| Statistics | 0.07 ms |
| Preparing | 0.01 ms |
| Unlocking tables | 0.01 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.01 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.04 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 11 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 10 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_htprotect/core/accounts.php:449 |
| 9 | HtpAccounts::privilegedGroupIds() | JROOT/administrator/components/com_htprotect/core/accounts.php:359 |
| 8 | HtpAccounts::snapshot() | JROOT/administrator/components/com_htprotect/core/accounts.php:35 |
| 7 | HtpAccounts::evaluate() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3149 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.47 ms Na de laatste zoekopdracht: 0.14 ms Zoekopdracht geheugen: 0.020 MB geheugen voor zoekopdracht: 28.175 MB Regels teruggegeven: 2
Identieke zoekopdrachten:
#87SELECT DISTINCT `user_id`
FROM `hmclx_user_usergroup_map`
WHERE `group_id` IN (8)
LIMIT 500
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_user_usergroup_map | range | NULL | PRIMARY | 8 | NULL | 8 | Using where; Using index for group-by; Using temporary |
| Status | Duration |
|---|
| Starting | 0.05 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.01 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.05 ms |
| Preparing | 0.01 ms |
| Creating tmp table | 0.08 ms |
| Executing | 0.00 ms |
| Sending data | 0.07 ms |
| Removing tmp table | 0.01 ms |
| Sending data | 0.01 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 10 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1550 |
| 9 | JDatabaseDriver->loadColumn() | JROOT/administrator/components/com_htprotect/core/accounts.php:371 |
| 8 | HtpAccounts::snapshot() | JROOT/administrator/components/com_htprotect/core/accounts.php:35 |
| 7 | HtpAccounts::evaluate() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3149 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.42 ms Na de laatste zoekopdracht: 0.10 ms Zoekopdracht geheugen: 0.021 MB geheugen voor zoekopdracht: 28.180 MB Regels teruggegeven: 2
SELECT `id`,`username`,`email`,`password`,`block`,`lastvisitDate`
FROM `hmclx_users`
WHERE `id` IN (613,800)
LIMIT 500
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_users | range | PRIMARY | PRIMARY | 4 | NULL | 2 | Using where |
| Status | Duration |
|---|
| Starting | 0.04 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.03 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.05 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.00 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 10 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1506 |
| 9 | JDatabaseDriver->loadAssocList() | JROOT/administrator/components/com_htprotect/core/accounts.php:390 |
| 8 | HtpAccounts::snapshot() | JROOT/administrator/components/com_htprotect/core/accounts.php:35 |
| 7 | HtpAccounts::evaluate() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3149 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.78 ms Na de laatste zoekopdracht: 0.25 ms Zoekopdracht geheugen: 0.161 MB geheugen voor zoekopdracht: 28.186 MB Regels teruggegeven: 1
SELECT `params`
FROM `hmclx_extensions`
WHERE `type` = 'component'
AND `element` = 'com_htprotect'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_extensions | ref | element_clientid,element_folder_clientid,extension | element_clientid | 402 | const | 1 | Using index condition; Using where |
| Status | Duration |
|---|
| Starting | 0.04 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.06 ms |
| Optimizing | 0.02 ms |
| Statistics | 0.14 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.28 ms |
| End of update loop | 0.02 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.04 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 11 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 10 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_htprotect/core/defs.php:3772 |
| 9 | HtpDefs::loadCached() | JROOT/administrator/components/com_htprotect/core/defs.php:815 |
| 8 | HtpDefs::effectiveVuln() | JROOT/administrator/components/com_htprotect/core/defs.php:3253 |
| 7 | HtpDefs::checkExtensions() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3170 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.96 ms Na de laatste zoekopdracht: 1.71 ms Zoekopdracht geheugen: 0.149 MB geheugen voor zoekopdracht: 28.320 MB Regels teruggegeven: 268
SELECT `element`,`type`,`folder`,`client_id`,`manifest_cache`,`enabled`
FROM `hmclx_extensions`
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_extensions | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 270 | |
| Status | Duration |
|---|
| Starting | 0.05 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.01 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 1.62 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.02 ms |
| closing tables | 0.01 ms |
| Query end | 0.04 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 9 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1506 |
| 8 | JDatabaseDriver->loadAssocList() | JROOT/administrator/components/com_htprotect/core/defs.php:3264 |
| 7 | HtpDefs::checkExtensions() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3170 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.78 ms Na de laatste zoekopdracht: 130.64 ms Zoekopdracht geheugen: 0.161 MB geheugen voor zoekopdracht: 28.324 MB Regels teruggegeven: 1
SELECT `params`
FROM `hmclx_extensions`
WHERE `type` = 'component'
AND `element` = 'com_htprotect'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_extensions | ref | element_clientid,element_folder_clientid,extension | element_clientid | 402 | const | 1 | Using index condition; Using where |
| Status | Duration |
|---|
| Starting | 0.16 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.06 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.03 ms |
| init | 0.08 ms |
| Optimizing | 0.05 ms |
| Statistics | 0.19 ms |
| Preparing | 0.05 ms |
| Executing | 0.00 ms |
| Sending data | 0.32 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 10 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 9 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_htprotect/core/defs.php:3810 |
| 8 | HtpDefs::saveCached() | JROOT/administrator/components/com_htprotect/core/defs.php:1023 |
| 7 | HtpDefs::refresh() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3195 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 5.23 ms Na de laatste zoekopdracht: 6.36 ms Zoekopdracht geheugen: 0.004 MB geheugen voor zoekopdracht: 28.861 MB
Identieke zoekopdrachten:
#94UPDATE `hmclx_extensions`
SET `params` = '{\"htp_shield\":{\"site_path\":\"\",\"sef_rules\":1,\"api_router\":1,\"api_mode\":\"route\",\"fastcgi_auth\":1,\"apache_options\":1,\"follow_symlink\":0,\"force_https\":1,\"www_mode\":0,\"canonical_host\":\"\",\"h_frame\":1,\"h_nosniff\":1,\"h_referrer\":\"strict-origin-when-cross-origin\",\"h_poweredby\":1,\"h_hsts\":0,\"h_hsts_sub\":0,\"h_coop\":0,\"h_permissions\":0,\"f_query\":1,\"f_rfi\":1,\"f_methods\":1,\"f_wpnoise\":1,\"htaccess_external\":0,\"shield_autoheal\":1,\"shield_autoheal_last\":0,\"mig_selfon_2415\":1,\"guard_dismissed\":0,\"x_shield\":1,\"x_sigs_off\":[],\"defs_version\":\"2026-07-15.9ac386\",\"mal_whitelist\":[],\"u_harden\":1,\"u_dirs\":[\"images\",\"media\"],\"emergency_lock\":0,\"notify_email\":\"pch.info@dubbelbit.nl\",\"notify_reminder_days\":14,\"unsub_secret\":\"knIOkiU01E3ceU0YZZ8ARjTQkWuTbqXAfktb1qjg6K0\",\"unsub_base\":\"https:\\/\\/www.efitec.nl\\/\",\"site_fp\":\"6d83c72d155aaa19f87ab9edd8cf222657b5b548\",\"swarm_contrib_id\":\"\",\"swarm_acked\":[],\"watch_manifest\":{\".htaccess\":\"dcb97f95087f2bdb336d0ffdcc300371ca6c4c51\",\"administrator\\/.htaccess\":\"2a00152a7d76a1d4a9444edf477c7404821a8b08\",\"images\\/.htaccess\":\"69714eb0929213f686d66baa144fceefbb395f8f\",\"media\\/.htaccess\":\"69714eb0929213f686d66baa144fceefbb395f8f\"},\"core_manifest\":{\"index.php\":\"2f1b60fc565276ae146bea9aaeadec93fb4dc87c\",\"administrator\\/index.php\":\"7078c5d7b2181900c509c93302f324e2dae228bf\"},\"core_jversion\":\"3.10.12\",\"accounts_watch\":1,\"account_baseline\":{\"613\":{\"id\":613,\"username\":\"admin\",\"email\":\"pch.info@dubbelbit.nl\",\"phash\":\"6300584d05e69c7f07ba2fb51a2f5ade41aeedd4\",\"block\":0,\"lastvisit\":\"2026-07-15 10:54:36\",\"pneeds\":0},\"800\":{\"id\":800,\"username\":\"dubbelbit\",\"email\":\"info@dubbelbit.nl\",\"phash\":\"081a5bae87c5a349a57ac9416a5157be4b8f95d5\",\"block\":0,\"lastvisit\":\"2025-11-06 17:15:16\",\"pneeds\":0}},\"admin_whitelist\":[],\"helix_ignore\":[],\"seo_watch\":1,\"compat_guard\":1,\"seo_cloaking_auto\":0,\"seo_whitelist\":[],\"seo_topic_ack\":[],\"seo_baseline\":{\"title\":\"Home\",\"out_domains\":{\"www.facebook.com\":1,\"nl.pinterest.com\":1,\"www.youtube.com\":1,\"www.s-bb.nl\":1,\"nieuw.efitec.nl\":1,\"xdebug.org\":1},\"shingles\":{\"511079512\":1,\"2918310184\":1,\"155886152\":1,\"3160688592\":1,\"3485062088\":1,\"585239104\":1,\"3828873704\":1,\"4087449296\":1,\"3631890208\":1,\"2453473432\":1,\"352088384\":1,\"1507055824\":1,\"1387258184\":1,\"96078016\":1,\"4120744744\":1,\"884599352\":1,\"148068952\":1,\"2322729328\":1,\"1647395640\":1,\"550572240\":1,\"2804985368\":1,\"2665301464\":1,\"3371643872\":1,\"1999195856\":1,\"412108984\":1,\"3675484672\":1,\"2196848680\":1,\"2599037872\":1,\"4081499304\":1,\"187337984\":1,\"362962264\":1,\"2094558736\":1,\"2787016200\":1,\"1792673952\":1,\"3358772584\":1,\"3190343216\":1,\"2235320368\":1,\"4225413856\":1,\"148784336\":1,\"4133289600\":1,\"1990767144\":1,\"265081816\":1,\"1454988472\":1,\"3545206312\":1,\"2836836760\":1,\"1552018832\":1,\"344452216\":1,\"461581872\":1,\"202494824\":1,\"3735037840\":1,\"3332537384\":1,\"2554787144\":1,\"746144872\":1,\"1848356288\":1,\"3951814824\":1,\"1464161728\":1,\"982788704\":1,\"3748426760\":1,\"136372440\":1,\"3214585776\":1,\"1332842344\":1,\"1366336928\":1,\"754226368\":1,\"1993946344\":1,\"140539032\":1,\"3458701480\":1,\"1779788808\":1,\"829495128\":1,\"258726864\":1,\"2313381704\":1,\"506576576\":1,\"682230128\":1,\"2799752896\":1,\"1200023392\":1,\"1387821168\":1,\"3867735952\":1,\"235572904\":1,\"211001480\":1,\"1209613064\":1,\"1950179312\":1,\"39928272\":1,\"2520740096\":1,\"810676984\":1,\"1550852192\":1,\"3946537872\":1,\"1061088320\":1,\"924937024\":1,\"2981285080\":1,\"4214313248\":1,\"2706907200\":1,\"4109595712\":1,\"2467453096\":1,\"1925217168\":1,\"254204696\":1,\"2797136096\":1,\"3557110600\":1,\"4041208904\":1,\"1327249520\":1,\"1607673584\":1,\"4007425464\":1,\"2632851624\":1,\"3330990656\":1,\"2693581640\":1,\"689915416\":1,\"4066896848\":1,\"480467872\":1,\"3008275536\":1,\"3101468488\":1,\"172199312\":1,\"650342624\":1,\"2553018880\":1,\"2609132040\":1,\"2991890336\":1,\"3462925544\":1,\"2964742568\":1,\"357174032\":1,\"1561660688\":1,\"1048480240\":1,\"1489547928\":1,\"208422712\":1,\"3778160000\":1,\"3789275216\":1,\"2776431456\":1,\"507422944\":1,\"4101744904\":1,\"942566752\":1,\"3196827536\":1,\"648166736\":1,\"1094268640\":1,\"1260128512\":1,\"3590796976\":1,\"1273715136\":1,\"4239054088\":1,\"1559046784\":1,\"4007417480\":1,\"7730296\":1,\"1458451704\":1,\"2911589176\":1,\"454621680\":1,\"1251844592\":1,\"4015838272\":1,\"1300147528\":1,\"1236487296\":1,\"3294019280\":1,\"4123225216\":1,\"670221008\":1,\"2571777288\":1,\"3627078176\":1,\"293222816\":1,\"281163600\":1,\"2508087208\":1,\"3543193024\":1,\"1915969656\":1,\"717056536\":1,\"848595304\":1,\"3107900104\":1,\"2589595704\":1,\"2034508136\":1,\"1977429088\":1,\"2584638584\":1,\"2493542936\":1,\"1158834928\":1,\"1531644320\":1,\"4102387360\":1,\"39764600\":1,\"4261163824\":1,\"1123389784\":1,\"2094010560\":1,\"1856123928\":1,\"376102376\":1,\"4096007544\":1,\"2256249280\":1,\"1618392856\":1,\"2709313920\":1,\"444641888\":1,\"3013023016\":1,\"4217705304\":1,\"2214186752\":1,\"716719120\":1,\"1972556728\":1,\"2438508112\":1,\"1820085032\":1,\"1223539912\":1,\"2846665840\":1,\"933003528\":1,\"2230427152\":1,\"1208455864\":1,\"2025534160\":1,\"1408784776\":1,\"2685059296\":1,\"3489792648\":1,\"1615724560\":1,\"8044840\":1,\"2316854528\":1,\"2550915448\":1,\"1211668720\":1,\"1935561680\":1,\"1828019016\":1,\"1827743704\":1,\"1337666672\":1,\"1911606592\":1,\"3178569384\":1,\"2552993816\":1,\"2123798152\":1,\"3761658400\":1,\"548688272\":1,\"2129684000\":1,\"4124423392\":1,\"1153004272\":1,\"796890520\":1,\"1247028480\":1,\"958748368\":1,\"1744512424\":1,\"647816080\":1,\"743882928\":1,\"3084540200\":1,\"3651199344\":1,\"109843936\":1,\"3303788176\":1,\"3393712720\":1,\"2772452800\":1,\"1345583752\":1,\"4138023008\":1,\"1630734352\":1,\"1587613576\":1,\"1950652592\":1,\"2777296976\":1,\"2621186584\":1,\"36106456\":1,\"2825573424\":1,\"303059736\":1,\"955024752\":1,\"4174757896\":1,\"335870296\":1,\"947878136\":1,\"885775072\":1,\"2836090264\":1,\"1479167544\":1,\"3195444184\":1,\"1373515616\":1,\"2703441304\":1,\"2999798000\":1,\"807202496\":1,\"2139078408\":1,\"3679148440\":1,\"4128820280\":1,\"4051291288\":1,\"524040760\":1,\"3226643448\":1,\"3914545768\":1,\"3485632672\":1,\"1455493656\":1,\"3040222736\":1,\"1738075592\":1,\"3987514200\":1,\"428036792\":1,\"2710735120\":1,\"3436957576\":1,\"3230827720\":1,\"1002378832\":1,\"477165832\":1,\"1378722152\":1,\"2798472384\":1,\"272556984\":1,\"351010464\":1,\"2168780672\":1,\"1806222752\":1,\"3716151024\":1,\"209155304\":1,\"2826036216\":1,\"420540632\":1,\"4203005848\":1,\"957468880\":1,\"1728849744\":1,\"4015778440\":1,\"1216866856\":1,\"4007963960\":1,\"3846677624\":1,\"3656753424\":1,\"75803256\":1,\"600705112\":1,\"1859028960\":1,\"2694091560\":1,\"2607914576\":1,\"2834052552\":1,\"3439897368\":1,\"2144818552\":1,\"3130333816\":1,\"3591606896\":1,\"1894249248\":1,\"4188555200\":1,\"245520800\":1,\"1682089672\":1,\"9149544\":1,\"3226699984\":1,\"1372800744\":1,\"2964205104\":1,\"722285192\":1,\"2322851088\":1,\"2139649696\":1,\"603889336\":1,\"3640799032\":1,\"1116378504\":1,\"3895415872\":1,\"1253935208\":1,\"528756504\":1,\"2284709784\":1,\"802473640\":1,\"3733678920\":1,\"361847392\":1,\"1232831160\":1,\"144058216\":1,\"1338885880\":1,\"992984272\":1,\"3773773072\":1,\"4182600\":1,\"2502992360\":1,\"4070217592\":1,\"547683160\":1,\"3290051432\":1,\"79724832\":1,\"821879880\":1,\"3181784208\":1,\"2105835160\":1,\"1048475128\":1,\"1530568368\":1,\"3978930832\":1,\"4141876912\":1,\"3134899488\":1,\"1235858440\":1,\"810201200\":1,\"3515040152\":1,\"2863190304\":1,\"1420257944\":1,\"798171424\":1,\"3843014608\":1,\"610676112\":1,\"1833740312\":1,\"3925377248\":1,\"2006124312\":1,\"3781864704\":1,\"3031336392\":1,\"4137422488\":1,\"3039953848\":1,\"1385104704\":1,\"4245224744\":1,\"4290332968\":1,\"2274655504\":1,\"1645581528\":1,\"2669455816\":1,\"3722712864\":1,\"1646278032\":1,\"2080430464\":1,\"1286501976\":1,\"1591713568\":1,\"1088809128\":1,\"3634194248\":1,\"3615937792\":1,\"3089178208\":1,\"3235297640\":1,\"1552428824\":1,\"1558271616\":1,\"2721862208\":1,\"1872388720\":1,\"1925908336\":1,\"1739818640\":1,\"1067862528\":1,\"4176326200\":1,\"1295895024\":1,\"1416323816\":1,\"252019184\":1,\"673687856\":1,\"1020035096\":1,\"1477984416\":1,\"798794864\":1,\"3895830512\":1,\"3877253568\":1,\"3725099576\":1,\"2100351152\":1,\"2474987096\":1,\"73942424\":1,\"13272208\":1,\"1943482168\":1,\"3977611416\":1,\"1547675656\":1,\"1718305248\":1,\"1732106904\":1,\"1643112200\":1,\"1345094056\":1,\"2907109104\":1,\"1613823168\":1,\"1646322024\":1},\"redirect_to\":\"\",\"ts\":1785610640},\"seo_overview_ts\":1785610637,\"seo_overview_finding\":[],\"core_overview_ts\":1784128054,\"core_overview_finding\":[],\"plugin_initialized\":1,\"quickicon_initialized\":1,\"autosecure\":0,\"autosecure_last\":0,\"tmp_autoclean\":0,\"tmp_keep\":[],\"autoupdate_notify\":0,\"autoupdate_ext\":1,\"autoupdate_all\":0,\"autoupdate_self\":1,\"autoupdate_manual\":0,\"autoupdate_mail_success\":0,\"autoupdate_include\":[],\"autoupdate_keep\":1,\"autoupdate_interval\":86400,\"autoupdate_schedule\":\"daily\",\"autoupdate_hour\":21,\"autoupdate_weekday\":5,\"autoupdate_grace\":3,\"autoupdate_malscan\":1,\"autoupdate_skip_major\":0,\"keep_update_sites\":1,\"keep_update_sites_except\":[],\"s_php\":1,\"s_types\":1,\"s_ext\":\"7z,avif,bmp,br,css,csv,doc,docx,eot,geojson,gif,gml,gpx,gz,htm,html,ico,ics,jp2,jpe,jpeg,jpg,js,json,kml,kmz,m4a,m4v,map,mjs,mov,mp3,mp4,mpeg,mpg,odp,ods,odt,oga,ogg,ogv,opus,otf,pdf,png,ppt,pptx,rar,rtf,svg,svgz,tif,tiff,ttf,txt,vtt,wasm,wav,webm,webmanifest,webp,woff,woff2,xls,xlsx,xml,xsl,zip\",\"s_files\":[\"administrator\\/components\\/com_akeeba\\/restore.php\",\"administrator\\/components\\/com_akeebabackup\\/restore.php\"],\"s_dirs_php\":[\"plugins\\/system\\/bfnetwork\"],\"s_dirs_static\":[],\"allow_paths\":[],\"s_dotfiles\":1,\"s_wellknown\":1,\"s_sensitive\":1,\"s_manifests\":0,\"s_sysdirs\":1,\"s_sysdirs_list\":[\"administrator\\/cache\",\"administrator\\/logs\",\"cache\",\"cli\",\"log\",\"logs\",\"tmp\"],\"p_compress\":1,\"p_precomp\":0,\"p_expires\":1,\"p_etag\":0,\"custom_top\":\"\",\"custom_bottom\":\"\",\"file_sha1\":\"dcb97f95087f2bdb336d0ffdcc300371ca6c4c51\",\"last_written\":\"2026-07-15 17:20:03\",\"last_test\":{\"checks\":[{\"label\":\"Home page reachable\",\"url\":\"https:\\/\\/www.efitec.nl\\/\",\"status\":200,\"ok\":true,\"note\":\"\"},{\"label\":\"Backend reachable (401 = password protection active)\",\"url\":\"https:\\/\\/www.efitec.nl\\/administrator\\/index.php\",\"status\":401,\"ok\":true,\"note\":\"\"},{\"label\":\"PHP shield active (test call is rejected with 403)\",\"url\":\"https:\\/\\/www.efitec.nl\\/htpx-canary-fbfbe897.php\\/htp\",\"status\":403,\"ok\":true,\"note\":\"\"},{\"label\":\"configuration.php blocked\",\"url\":\"https:\\/\\/www.efitec.nl\\/configuration.php\",\"status\":403,\"ok\":true,\"note\":\"\"}],\"regression\":false,\"reason\":\"\",\"time\":\"2026-07-15 15:20:03\"},\"guard_dir\":\"\",\"guard_recover\":\"263c210ee005a46813c42d75dd82d7144cb9b918b4356d8c60a8f9225963fe48\",\"welcome_sent\":1,\"welcome_green_since\":0,\"jed_review_ack\":\"\",\"jed_mail_last\":0,\"htaccess_cap\":[]},\"htp_defs\":{\"schema\":1,\"version\":\"2026-07-31.fa71fe\",\"signatures\":[{\"id\":\"jce-profiles-import\",\"label\":\"JCE Profil-Import (CVE-2026-48907)\",\"label_en\":\"JCE profile import (CVE-2026-48907)\",\"desc\":\"Unauthentifizierter Profil-Import im JCE-Editor - Beginn der aktuellen RCE-Kette (schaltet PHP-Uploads frei). Kein legitimer Frontend-Aufruf.\",\"desc_en\":\"Unauthenticated profile import in the JCE editor - start of the current RCE chain (enables PHP uploads). No legitimate frontend call.\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*task=profiles\\\\.import)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"jce-rpc-upload\",\"label\":\"JCE Webshell-Upload via plugin.rpc (CVE-2026-48907)\",\"label_en\":\"JCE webshell upload via plugin.rpc (CVE-2026-48907)\",\"desc\":\"Datei-Upload \\u00fcber den JCE-Dateibrowser (plugin.rpc, method=upload). Greift nur im Frontend; eingeloggte Autoren (legitimer Editor-Upload) bleiben unber\\u00fchrt.\",\"desc_en\":\"File upload via the JCE file browser (plugin.rpc, method=upload). Applies only
on the frontend; logged-in authors (legitimate editor upload) are unaffected.\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*task=plugin\\\\.rpc)(?=.*method=upload)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":null},{\"id\":\"jce-imgmanager\",\"label\":\"JCE Image Manager (Alt-Exploit)\",\"label_en\":\"JCE Image Manager (legacy exploit)\",\"desc\":\"Klassischer unauthentifizierter Datei-Upload \\u00fcber den JCE-Bildmanager (sehr alte JCE-Versionen).\",\"desc_en\":\"Classic unauthenticated file upload via the JCE image manager (very old JCE versions).\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*plugin=imgmanager)(?=.*method=form)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":null},{\"id\":\"novarain-nrframework\",\"label\":\"Novarain \\/ Tassos Framework (com_ajax include)\",\"label_en\":\"Novarain \\/ Tassos Framework (com_ajax include)\",\"desc\":\"CVE-2026-21627: unauthentifizierte PHP-Datei-Einbindung \\u00fcber plg_system_nrframework via com_ajax (task=include).\",\"desc_en\":\"CVE-2026-21627: unauthenticated PHP file inclusion via plg_system_nrframework through com_ajax (task=include).\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*nrframework)(?=.*task=include)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"astroid-ajax\",\"label\":\"Astroid Framework (AJAX-Endpunkt)\",\"label_en\":\"Astroid Framework (AJAX endpoint)\",\"desc\":\"CVE-2026-21628: ungepr\\u00fcfter Astroid-AJAX-Endpunkt (Upload\\/Installation). Coarse-Match auf com_ajax + astroid.\",\"desc_en\":\"CVE-2026-21628: unchecked Astroid AJAX endpoint (upload\\/installation). Coarse match
on com_ajax + astroid.\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*(plugin|template|view)=astroid)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"helix3-ajax\",\"label\":\"Helix3 (JoomShaper): unauth. com_ajax-Handler (Datei schreiben\\/l\\u00f6schen)\",\"label_en\":\"Helix3 (JoomShaper): unauth com_ajax handler (file write\\/delete)\",\"desc\":\"Helix3 < 3.1.1: der Ajax-Handler onAjaxHelix3 pr\\u00fcfte weder Login noch Rechte. Trifft gezielt die gef\\u00e4hrlichen Unauth-Aktionen im POST-Body: save (Layout-JSON ins aktive Template schreiben), remove (Datei l\\u00f6schen via Path-Traversal), import (Template-Style-Settings \\u00fcberschreiben) sowie upload_image\\/remove_image\\/updateFonts. Legitime Gast-Aktionen (voting, load) und eingeloggte Template-Nutzung \",\"desc_en\":\"Helix3 < 3.1.1: the onAjaxHelix3 ajax handler checked neither login nor permission. Targets the dangerous unauth POST-body actions: save (write layout JSON into the active template), remove (delete a file via path traversal), import (overwrite template style settings) plus upload_image\\/remove_image\\/updateFonts. Legitimate guest actions (voting, load)
and logged-in template use are unaffected. Fix:\",\"default\":1,\"qs\":\"data(?:\\\\[|%5b)action(?:\\\\]|%5d)=(?:save|remove|import|updatefonts)|action=(?:upload_image|remove_image)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"helix3-comajax\",\"label\":\"Helix3 (JoomShaper): unauth. com_ajax-Dispatcher (Datei-Write\\/Delete, Style-Injektion)\",\"label_en\":\"Helix3 (JoomShaper): unauth com_ajax dispatcher (file write\\/delete, style injection)\",\"desc\":\"Helix3 < 3.1.1: der Front-Dispatcher (option=com_ajax mit plugin=helix3) rief onAjaxHelix3 VOR jeder Token-\\/Rechtepr\\u00fcfung auf - unauthentifiziert save\\/import\\/remove\\/resetLayout\\/updateFonts\\/fontVariants (Datei-Schreiben, Path-Traversal-L\\u00f6schen, Template-Style-Injektion, Stored XSS). Blockt jeden GAST-Aufruf dieses Dispatchers im Frontend (Defense-in-Depth, f\\u00e4ngt auch laufende Scans) - erg\\u00e4nzt d\",\"desc_en\":\"Helix3 < 3.1.1: the front-end dispatcher (option=com_ajax with plugin=helix3) invoked onAjaxHelix3 BEFORE any token\\/permission check - unauthenticated save\\/import\\/remove\\/resetLayout\\/updateFonts\\/fontVariants (file write, path-traversal delete, template style injection, stored XSS). Blocks every GUEST call of this dispatcher
on the front end (defense in depth, also catches ongoing scans) - complemen\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*plugin=helix3\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"helixultimate-comajax\",\"label\":\"Helix Ultimate (JoomShaper): unauth. com_ajax-Dispatcher (Men\\u00fc-Write\\/Datei\\/Export)\",\"label_en\":\"Helix Ultimate (JoomShaper): unauth com_ajax dispatcher (menu write\\/file\\/export)\",\"desc\":\"Helix Ultimate < 2.2.7: der com_ajax-Handler onAjaxHelixultimate (option=com_ajax mit plugin=helixultimate, Action im task-Param) lief VOR jeder Login-\\/Rechtepr\\u00fcfung - ein anonymer Angreifer konnte in die Men\\u00fc-Einstellungen schreiben (Stored XSS bis in die Admin-Sitzung), Dateien per Path-Traversal beliebig l\\u00f6schen, einen Open Redirect ausl\\u00f6sen und das Template ungesch\\u00fctzt exportieren. Blockt\",\"desc_en\":\"Helix Ultimate < 2.2.7: the com_ajax handler onAjaxHelixultimate (option=com_ajax with plugin=helixultimate, action in the task param) ran BEFORE any login\\/permission check - an anonymous attacker could write into the menu settings (stored XSS reaching the admin session), delete files anywhere via path traversal, trigger an open redirect
and export the template unprotected. Blocks every GUEST call\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*plugin=helixultimate\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"comajax-include\",\"label\":\"com_ajax: Datei-Einbindung (generisch)\",\"label_en\":\"com_ajax: file inclusion (generic)\",\"desc\":\"F\\u00e4ngt unbekannte LFI-L\\u00fccken derselben Klasse ab: com_ajax mit task=include\\/require. Frontend.\",\"desc_en\":\"Catches unknown LFI holes of the same class: com_ajax with task=include\\/require. Frontend.\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*task=(include|require)(_once)?)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"sppagebuilder-uploadicon\",\"label\":\"SP Page Builder: unauthentifizierter Icon-Upload (RCE)\",\"label_en\":\"SP Page Builder: unauthenticated icon upload (RCE)\",\"desc\":\"Zero-Day in SP Page Builder bis 6.6.1: der asset-Controller (task=asset.uploadCustomIcon) hatte keinerlei Zugriffs-\\/Login-Pr\\u00fcfung - unauthentifizierter Datei-Upload nach \\/media\\/com_sppagebuilder\\/assets\\/iconfont\\/ - RCE. Nur Mini-WAF (G\\u00e4ste), da eingeloggte Builder den Endpunkt legitim nutzen.\",\"desc_en\":\"Zero-day in SP Page Builder up to 6.6.1: the asset controller (task=asset.uploadCustomIcon) had no access\\/login check - unauthenticated file upload to \\/media\\/com_sppagebuilder\\/assets\\/iconfont\\/ - RCE. Mini-WAF only (guests), since logged-in builders use the endpoint legitimately.\",\"default\":1,\"qs\":\"(?=.*option=com_sppagebuilder)(?=.*task=asset\\\\.uploadCustomIcon)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":null},{\"id\":\"dpcalendar-createdby-sqli\",\"label\":\"DPCalendar: unauth. SQL-Injection (Autor-Filter)\",\"label_en\":\"DPCalendar: unauth SQL injection (author filter)\",\"desc\":\"DPCalendar Blind-SQLi (Joomla 4.4-6 < 10.11.2, J3 < 8.19.4): der Frontend-Autor-Filter filter_created_by (option=com_dpcalendar, view=events) floss in skalarer Form ungecastet in a.created_by IN (...) - anonymes Auslesen beliebiger DB-Tabellen (nur lesend). Blockt Gast-Anfragen, deren filter_created_by kein reiner Integer ist (legitim = Autor-IDs\\/Ziffern) -> FP-frei. Fix 10.11.2 \\/ 8.19.4.\",\"desc_en\":\"DPCalendar blind SQLi (Joomla 4.4-6 < 10.11.2, J3 < 8.19.4): the front-end author filter filter_created_by (option=com_dpcalendar, view=events) flowed uncast into a.created_by IN (...) in its scalar form - anonymous read of arbitrary DB tables (read-only). Blocks guest requests whose filter_created_by is not a pure integer (legit = author IDs\\/digits) -> FP-free. Fix 10.11.2 \\/ 8.19.4.\",\"default\":1,\"qs\":\"(?=.*option=com_dpcalendar)(?=.*filter_created_by=[0-9,]*[^0-9,&])\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_dpcalendar\"},{\"id\":\"acym-entityselect-sqli\",\"label\":\"AcyMailing: unauth. SQL-Injection (Entity-Select Spaltenliste)\",\"label_en\":\"AcyMailing: unauth SQL injection (entity-select column list)\",\"desc\":\"CVE-2026-56292 (AcyMailing 6.0.0-10.11.0): der Frontend-Endpunkt EntitySelectController::loadEntityFront (option=com_acym, task=loadEntityFront) nahm die Request-Parameter columns\\/join_table ungeprueft in die SELECT-Spaltenliste von UserClass::getMatchingElements auf - ein anonymer Besucher konnte per Subquery beliebige DB-Tabellen (inkl. Passwort-Hashes) auslesen. Blockt GAST-Aufrufe dieses Tasks\",\"desc_en\":\"CVE-2026-56292 (AcyMailing 6.0.0-10.11.0): the front-end endpoint EntitySelectController::loadEntityFront (option=com_acym, task=loadEntityFront) placed the request parameters columns\\/join_table unchecked into the SELECT column list of UserClass::getMatchingElements - an anonymous visitor could read arbitrary DB tables (incl. password hashes) via a subquery. Blocks GUEST calls of this task whose c\",\"default\":1,\"qs\":\"(?=.*option=com_acym)(?=.*task=loadEntityFront)(?=.*(?:columns|join_table|join)=[^&]*(?:\\\\(|%28|%2528|\\\\s|%20|\\\\+))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_acym\"},{\"id\":\"quix-article-sqli\",\"label\":\"Quix Page Builder: unauth. SQL-Injection (Einzel-Artikel-AJAX)\",\"label_en\":\"Quix Page Builder: unauth SQL injection (single-article AJAX)\",\"desc\":\"Quix (ThemeXpert, Free UND Pro) bis 6.2.0, inkl. der 5.x-Reihe: der oeffentliche AJAX-Endpunkt (option=com_quix, task=ajax, element=joomla-article) ruft QuixJoomlaArticleElement::getAjax() ohne Login-\\/Token-\\/Lizenz-Pruefung; die Artikel-ID kommt base64-kodiert im data-Parameter und wird in articleExist() UNGECASTET in die DB-Query konkateniert -> unauthentifizierte, fehler-basierte SQL-Injection (\",\"desc_en\":\"Quix (ThemeXpert, Free
AND Pro) up to 6.2.0, incl. the 5.x line: the public AJAX endpoint (option=com_quix, task=ajax, element=joomla-article) calls QuixJoomlaArticleElement::getAjax() with no login\\/token\\/license check; the article id arrives base64-encoded in the data parameter
and is concatenated UNCAST into the DB query in articleExist() -> unauthenticated error-based SQL injection (CVSS 8.7). \",\"default\":1,\"qs\":\"(?=.*option=com_quix)(?=.*task=ajax\\\\b)(?=.*element=joomla-article\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_quix\"},{\"id\":\"joomcck-tags-sqli\",\"label\":\"JoomCCK: unauth. SQL-Injection (Tag-Verwaltung)\",\"label_en\":\"JoomCCK: unauth SQL injection (tag management)\",\"desc\":\"CVE-2026-49048 (JoomCCK 6.x vor 6.4.1): der Front-End-Task tags.save\\/tags.delete (option=com_joomcck) lief OHNE Token-\\/Login-\\/Rechte-Pruefung und schob den Request-Parameter tag (getString) roh - mit Double-Quote-Ausbruch - in ZWEI aufeinanderfolgende SQL-Statements (Existenz-SELECT + UPDATE). Ein anonymer Besucher konnte die Datenbank auslesen und veraendern (stacked\\/error-based SQLi). Blockt jed\",\"desc_en\":\"CVE-2026-49048 (JoomCCK 6.x before 6.4.1): the front-end task tags.save\\/tags.delete (option=com_joomcck) ran with NO token\\/login\\/permission check
and concatenated the request parameter tag (getString) raw - with a double-quote breakout - into TWO consecutive SQL statements (existence SELECT + UPDATE). An anonymous visitor could read
and modify the database (stacked\\/error-based SQLi). Blocks every \",\"default\":1,\"qs\":\"(?=.*option=com_joomcck)(?=.*task=tags\\\\.(?:save|delete))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_joomcck\"},{\"id\":\"gridbox-store-register\",\"label\":\"Balbooa Gridbox: unauth. Konto-Erstellung (store.register)\",\"label_en\":\"Balbooa Gridbox: unauth account creation (store.register)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, gemeldet 2026-07-28, Fix in 2.20.2 (29.07.2026). Der Front-End-Task store.register lief OHNE Login\\/Token und legte ein Joomla-Konto mit FREI WAEHLBARER Usergruppe plus sofort gueltiger Session an (unauth Privilege Escalation). Blockt jeden Gast-Aufruf dieses Tasks. Kosten: falls die Site die Gridbox-eigene Frontend-Registrierung nu\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to
and incl. 2.20.1 - actively exploited, reported 2026-07-28, fixed in 2.20.2 (29 Jul 2026). The front-end task store.register ran WITHOUT login\\/token
and created a Joomla account with an ARBITRARY usergroup plus an immediately valid session (unauth privilege escalation). Blocks every guest call of this task. Cost: if the site uses Gridbox front-end registration (\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=store(\\\\.|%2e)register)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":\"com_gridbox\"},{\"id\":\"gridbox-uploader-showimage-read\",\"label\":\"Balbooa Gridbox: unauth. Datei-Lesen (uploader.showImage)\",\"label_en\":\"Balbooa Gridbox: unauth arbitrary file read (uploader.showImage)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, Fix in 2.20.2 (29.07.2026). Der Front-End-Task uploader.showImage laed ohne Login den Query-Parameter image= und gibt bei Nicht-Bildern die Datei roh aus (fopen+fpassthru) -> unauth Arbitrary File Read, u. a. configuration.php. Trifft JEDE Gridbox-Installation. SURGICAL: greift NUR, wenn image= ein Angriffsmuster enthaelt (Pfad-Kle\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to
and incl. 2.20.1 - actively exploited, fixed in 2.20.2 (29 Jul 2026). The front-end task uploader.showImage reads the query parameter image= without login
and, for non-images, dumps the file raw (fopen+fpassthru) -> unauth arbitrary file read incl. configuration.php. Hits EVERY Gridbox install. SURGICAL: fires ONLY when image= contains an attack pattern (travers\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=uploader(\\\\.|%2e)showImage)(?=.*image=(?:%2f|\\/|[a-z]:|[a-z]%3a|[^&]*(?:\\\\.\\\\.|%2e%2e|\\\\.php|%2ephp|%00|php:|php%3a|:%2f%2f|:\\/\\/)))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":\"com_gridbox\"},{\"id\":\"gridbox-uploader-savephoto\",\"label\":\"Balbooa Gridbox: unauth. Datei-Schreiben (uploader.savePhotoEditorImage)\",\"label_en\":\"Balbooa Gridbox: unauth arbitrary file write (uploader.savePhotoEditorImage)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, Fix in 2.20.2 (29.07.2026). Der Front-End-Task uploader.savePhotoEditorImage schreibt eine beliebige Datei (inkl. .php) in den Webroot; der Zieldateiname liegt im POST-Body (php:\\/\\/input) und ist fuer die .htaccess unsichtbar, und eingeloggte Redakteure nutzen den Endpunkt legitim. Daher waf_only + scope=guest: NUR im Echtzeit-Plugi\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to
and incl. 2.20.1 - actively exploited, fixed in 2.20.2 (29 Jul 2026). The front-end task uploader.savePhotoEditorImage writes an arbitrary file (incl. .php) into the webroot; the target filename is in the POST body (php:\\/\\/input), invisible to .htaccess,
and logged-in editors use the endpoint legitimately. Hence waf_only + scope=guest: enforced ONLY in the real-t\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=uploader(\\\\.|%2e)savePhotoEditorImage)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_gridbox\"},{\"id\":\"baforms-signature-rce\",\"label\":\"Balbooa Forms: unauth. RCE (Signature-Feld, CVE-2026-65880)\",\"label_en\":\"Balbooa Forms: unauth RCE (signature field, CVE-2026-65880)\",\"desc\":\"Balbooa Forms (com_baforms) bis inkl. 2.4.2.1 - CVE-2026-65880 (CVSS 10.0), aktiv ausgenutzt, Fix erst 2.4.3. Beim Absenden eines Formulars mit SIGNATURE-Feld (task=form.sendMessage) verwendet FormModel::saveSignature den vom Angreifer im Feld-JSON gelieferten Funktionsnamen dynamisch als aufgerufene Funktion mit angeh\\u00e4ngtem Wert - unauthentifizierte Remote Code Execution. Der legitime Wert ist i\",\"desc_en\":\"Balbooa Forms (com_baforms) up to
and incl. 2.4.2.1 - CVE-2026-65880 (CVSS 10.0), actively exploited, fixed only in 2.4.3. Submitting a form with a SIGNATURE field (task=form.sendMessage) makes FormModel::saveSignature use the attacker-supplied function name
from the field JSON dynamically as the called function with an appended value - unauthenticated remote code execution. The legitimate value i\",\"default\":1,\"qs\":\"(?=.*\\\\bmethod[^a-z0-9]{1,6}(?:system|exec|shell_exec|passthru|assert|popen|proc_open|pcntl_exec|file_get_contents|readfile|show_source|highlight_file|fopen|scandir|phpinfo|eval|create_function|call_user_func)\\\\b)(?=.*\\\\bimage\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":1,\"trigger\":\"com_baforms\"},{\"id\":\"traversal-encoded\",\"label\":\"Pfad-Klettern (kodierte Varianten)\",\"label_en\":\"Path traversal (encoded variants)\",\"desc\":\"Erg\\u00e4nzt den Standard-Filter um Umgehungstricks: ....\\/\\/ , doppelte Kodierung (%252e), %c0%ae, %2e%2e%5c.\",\"desc_en\":\"Extends the standard filter with bypass tricks: ....\\/\\/ , double encoding (%252e), %c0%ae, %2e%2e%5c.\",\"default\":1,\"qs\":\"(\\\\.{3,}\\/|%252e|%c0%a[ef]|%2e%2e%5c|\\\\.\\\\.%5c)\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"php-wrapper-uri\",\"label\":\"PHP-Stream-Wrapper im Pfad\",\"label_en\":\"PHP stream wrapper in the path\",\"desc\":\"Blockiert php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ , expect:\\/\\/ u. a. direkt im angefragten Pfad.\",\"desc_en\":\"Blocks php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ , expect:\\/\\/ etc. directly in the requested path.\",\"default\":1,\"qs\":null,\"uri\":\"(?:php|phar|data|expect|glob|zlib|zip):\\/\",\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"api-config-leak\",\"label\":\"Joomla-API Konfigurations-Leak\",\"label_en\":\"Joomla API configuration leak\",\"desc\":\"CVE-2023-23752: sch\\u00fctzt den Endpunkt \\/api\\/...\\/v1\\/config\\/application auch ohne komplette API-Sperre.\",\"desc_en\":\"CVE-2023-23752: protects the \\/api\\/...\\/v1\\/config\\/application endpoint even without a complete API block.\",\"default\":1,\"qs\":null,\"uri\":\"^api\\/index\\\\.php\\/v[0-9]+\\/config\",\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"php-object-injection\",\"label\":\"PHP Object Injection (serialisierte Payload)\",\"label_en\":\"PHP object injection (serialised payload)\",\"desc\":\"Serialisiertes PHP-Objekt in einem Parameter (O:\\/C:<L\\u00e4nge>:) - typischer Einstieg f\\u00fcr Object-Injection\\/POP-Ketten. Kommt in normalen Anfragen nicht vor.\",\"desc_en\":\"Serialised PHP object in a parameter (O:\\/C:<length>:) - typical entry point for object injection\\/POP chains. Does not occur in normal requests.\",\"default\":1,\"qs\":\"(?<![a-z0-9])[oc]:[0-9]{1,4}:\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"stream-wrapper-param\",\"label\":\"PHP-Stream-Wrapper in Parameter\",\"label_en\":\"PHP stream wrapper in a parameter\",\"desc\":\"php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ u. a. als Parameterwert - LFI\\/RCE-Vektor. Erg\\u00e4nzt die Pfad-Variante (php-wrapper-uri).\",\"desc_en\":\"php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ etc. as a parameter value - LFI\\/RCE vector. Complements the path variant (php-wrapper-uri).\",\"default\":1,\"qs\":\"(php|phar|data|expect|glob|zlib|zip):\\/{2}\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"param-traversal\",\"label\":\"Pfad-Klettern im Parameter\",\"label_en\":\"Path traversal in a parameter\",\"desc\":\"Mehrfaches ..\\/ als Parameterwert - generisches Directory-Traversal\\/LFI in beliebigen Komponenten.\",\"desc_en\":\"Repeated ..\\/ as a parameter value - generic directory traversal\\/LFI in any component.\",\"default\":1,\"qs\":\"=(\\\\.\\\\.\\/){2,}\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null}],\"vuln_extensions\":[{\"element\":\"aimycaptchalessformguard\",\"type\":\"plugin\",\"folder\":\"captcha\",\"name\":\"Aimy Captcha-Less Form Guard\",\"below\":\"20.1\",\"above\":\"17.0\",\"severity\":\"high\",\"note\":\"Sicherheitsl\\u00fccke in 18.0 bis 20.0, vom Hersteller in 20.1 behoben (freie und PRO-Edition betroffen). Kein Workaround - auf Aimy Captcha-Less Form Guard 20.1 oder neuer aktualisieren.\",\"note_en\":\"Security issue in 18.0 to 20.0, fixed by the vendor in 20.1 (free
and PRO edition affected). No workaround - update to Aimy Captcha-Less Form Guard 20.1 or newer.\",\"advisory\":\"https:\\/\\/www.aimy-extensions.com\\/joomla\\/captcha-less-form-guard.html\",\"advisory_en\":\"https:\\/\\/www.aimy-extensions.com\\/joomla\\/captcha-less-form-guard.html\"},{\"element\":\"com_easystore\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EasyStore (JoomShaper)\",\"below\":\"2.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere unauthentifizierte SQL-Injections (CVE-2026-65759 ff.). Auf EasyStore 2.0.2 oder neuer aktualisieren.\",\"note_en\":\"Multiple unauthenticated SQL injections (CVE-2026-65759 ff.). Update to EasyStore 2.0.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65759\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65759\"},{\"element\":\"com_splms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP LMS (JoomShaper)\",\"below\":\"4.1.4\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-48909: unauth. Code-Ausf\\u00fchrung durch unsichere Cookie-Deserialisierung. Auf SP LMS 4.1.4 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48909: unauthenticated code execution via insecure cookie deserialization. Update to SP LMS 4.1.4 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-48909\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-48909\"},{\"element\":\"com_osmembership\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Membership Pro (JoomDonation)\",\"below\":\"4.6.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-62415: kritische L\\u00fccke durch unsichere Standardkonfiguration. Auf Membership Pro 4.6.2 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-62415: critical flaw caused by an insecure default configuration. Update to Membership Pro 4.6.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-62415\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-62415\"},{\"element\":\"com_convertforms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Convert Forms (Tassos)\",\"below\":\"5.2.3\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische L\\u00fccken bis 5.2.2 (Datei-L\\u00f6schung, Datenleck; CVE-2024-40744). Auf Convert Forms 5.2.3 oder neuer aktualisieren.\",\"note_en\":\"Multiple critical flaws up to 5.2.2 (arbitrary file deletion, data exposure; CVE-2024-40744). Update to Convert Forms 5.2.3 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2024-40744\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2024-40744\"},{\"element\":\"sourcerer\",\"type\":\"plugin\",\"folder\":\"editors-xtd\",\"name\":\"Sourcerer (Regular Labs)\",\"below\":\"12.2.9\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2025-22204: Code-Injection durch mangelnde Rechtepr\\u00fcfung. Auf Sourcerer 12.2.9 oder neuer aktualisieren.\",\"note_en\":\"CVE-2025-22204: code injection due to missing permission checks. Update to Sourcerer 12.2.9 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-22204\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-22204\"},{\"element\":\"com_easydiscuss\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EasyDiscuss (StackIdeas)\",\"below\":\"5.0.16\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-21625: ACL-Umgehung im JSON-Output (Zugriff auf gesch\\u00fctzte Forendaten). Auf EasyDiscuss 5.0.16 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21625: access-control bypass in the JSON output exposing protected forum data. Update to EasyDiscuss 5.0.16 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-21625\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-21625\"},{\"element\":\"com_komento\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Komento (StackIdeas)\",\"below\":\"4.0.8\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2025-54294: SQL-Injection, ausnutzbar durch unprivilegierte Nutzer. Auf Komento 4.0.8 oder neuer aktualisieren.\",\"note_en\":\"CVE-2025-54294: SQL injection exploitable by unprivileged users. Update to Komento 4.0.8 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-54294\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-54294\"},{\"element\":\"nrframework\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Novarain \\/ Tassos Framework\",\"below\":\"6.0.38\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-21627: unauthentifizierte PHP-Einbindung via com_ajax. Auf 6.0.38 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21627: unauthenticated PHP inclusion via com_ajax. Update to 6.0.38 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/joomla-tassos-framework-novarain-framework-sicherheitsluecke\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/joomla-tassos-framework-novarain-framework-sicherheitsluecke\"},{\"element\":\"astroid\",\"type\":\"library\",\"folder\":\"\",\"name\":\"Astroid Framework\",\"below\":\"3.3.11\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-21628: unauthentifizierter Datei-Upload via AJAX-Endpunkt (Dropper in \\/images\\/). Auf 3.3.13 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21628: unauthenticated file upload via AJAX endpoint (dropper in \\/images\\/). Update to 3.3.13 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/joomla-astroid-framework-sicherheitsluecke-vulnerability\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/joomla-astroid-framework-sicherheitsluecke-vulnerability\"},{\"element\":\"helix3\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Helix3 (JoomShaper)\",\"below\":\"3.1.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Unauthentifizierter com_ajax-Handler (onAjaxHelix3) ohne Login-\\/Rechtepr\\u00fcfung: Angreifer k\\u00f6nnen Dateien ins aktive Template schreiben oder per Path-Traversal l\\u00f6schen (save\\/remove\\/import). Auf Helix3 3.1.1 oder neuer aktualisieren.\",\"note_en\":\"Unauthenticated com_ajax handler (onAjaxHelix3) with no login or permission check: attackers can write files into the active template or delete files via path traversal (save\\/remove\\/import). Update to Helix3 3.1.1 or newer.\",\"advisory\":\"https:\\/\\/htprotect.org\\/helix3\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/helix3\"},{\"element\":\"helixultimate\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Helix Ultimate (JoomShaper)\",\"below\":\"2.2.7\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Kritische unauth. L\\u00fccke in ALLEN Versionen < 2.2.7: der com_ajax-Handler onAjaxHelixultimate lief VOR jeder Rechtepr\\u00fcfung - anonym in die Men\\u00fcs schreiben (Stored XSS in den Admin), Path-Traversal-L\\u00f6schen, Open Redirect, Template-Export. Auf 2.2.7 updaten (Plugin UND Template). HTProtects Mini-WAF blockt den Aufruf bereits. NICHT mit Helix3 verwechseln.\",\"note_en\":\"Critical unauth flaw in ALL versions below 2.2.7: the com_ajax handler onAjaxHelixultimate ran before any permission check - anonymous menu writes (stored XSS reaching the admin), path-traversal delete, open redirect, template export. Update to 2.2.7 (plugin
AND template). HTProtect mini-WAF already blocks the call. Not to be confused with Helix3.\",\"advisory\":\"https:\\/\\/htprotect.org\\/helix-ultimate\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/helix-ultimate\"},{\"element\":\"com_baforms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Balbooa Forms\",\"below\":\"2.4.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Aktiver Zero-Day (RCE), ALLE Versionen bis 2.4.0: der Upload-Endpoint form.uploadAttachmentFile pr\\u00fcft weder Login\\/Token noch Dateityp - ein anonymer Angreifer kann eine PHP-Datei hochladen und ausf\\u00fchren. NOCH KEIN Patch. Sofortma\\u00dfnahme: Upload-Formulare depublizieren. HTProtects Gast-Upload-Schutz blockt den ausf\\u00fchrbaren Upload bereits.\",\"note_en\":\"Active zero-day (RCE), ALL versions up to 2.4.0: the upload endpoint form.uploadAttachmentFile checks neither login\\/token nor file type - an anonymous attacker can upload
and run a PHP file. NO patch yet. Interim: unpublish forms with upload fields. The HTProtect guest-upload filter already blocks the executable upload.\",\"advisory\":\"https:\\/\\/htprotect.org\\/balbooa-forms\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/balbooa-forms\"},{\"element\":\"com_jce\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JCE Editor\",\"below\":\"2.9.99.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-48907: unauthentifizierter Webshell-Upload (profiles.import + plugin.rpc). Dringend auf JCE 2.9.99.6 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48907: unauthenticated webshell upload (profiles.import + plugin.rpc). Urgently update to JCE 2.9.99.6 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/jce-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/jce-sicherheitsluecke-joomla\"},{\"element\":\"com_rsfiles\",\"type\":\"component\",\"folder\":\"\",\"name\":\"RSFiles!\",\"below\":\"1.17.12\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Aktiver unauthentifizierter Datei-Upload -> RCE, ALLE Versionen bis 1.17.11: der Frontend-Upload (task=rsfiles.upload) pr\\u00fcft weder Login\\/Token noch Dateiendung - ein anonymer Angreifer l\\u00e4dt eine .php nach \\/downloads bzw. \\/briefcase und f\\u00fchrt sie aus. Dringend auf 1.17.12 aktualisieren. HTProtects Gast-Upload-Schutz blockt den ausf\\u00fchrbaren Upload bereits.\",\"note_en\":\"Active unauthenticated file upload -> RCE, ALL versions up to 1.17.11: the front-end upload (task=rsfiles.upload) checks neither login\\/token nor file extension - an anonymous attacker uploads a .php into \\/downloads or \\/briefcase
and executes it. Update to 1.17.12 urgently. The HTProtect guest-upload filter already blocks the executable upload.\",\"advisory\":\"https:\\/\\/www.rsjoomla.com\\/blog\\/view\\/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html\",\"advisory_en\":\"https:\\/\\/www.rsjoomla.com\\/blog\\/view\\/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html\"},{\"element\":\"com_edocman\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EDocman\",\"below\":\"3.9\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Unauthentifizierte SQL-Injection (alle Versionen bis 3.8): ein anonymer Besucher schleust ueber einen Filter-Parameter eines oeffentlichen Frontend-Endpunkts SQL in eine ungequotete DB-Abfrage ein und kann die Datenbank auslesen (bis hin zu Zugangsdaten). Der genaue Vektor ist bewusst nicht veroeffentlicht. Dringend auf EDocman 3.9.0 aktualisieren.\",\"note_en\":\"Unauthenticated SQL injection (all versions up to 3.8): an anonymous visitor injects SQL through a filter parameter of a public front-end endpoint into an unquoted DB query
and can read the database (up to credentials). The exact vector is deliberately undisclosed. Update to EDocman 3.9.0 urgently.\",\"advisory\":\"https:\\/\\/joomdonation.com\\/forum\\/edocman\\/82813-edocman-3-9-0-security-release---important-update-recommended.html\",\"advisory_en\":\"https:\\/\\/joomdonation.com\\/forum\\/edocman\\/82813-edocman-3-9-0-security-release---important-update-recommended.html\"},{\"element\":\"com_foranalytics\",\"type\":\"component\",\"folder\":\"\",\"name\":\"4Analytics\",\"below\":\"5.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Zwei unauthentifizierte Sicherheitsluecken (CVE-2026-57833 + CVE-2026-58077) in ALLEN Versionen vor 5.0.2 - ein anonymer Angreifer braucht keinen Login. Hersteller Weeblr stuft beide als kritisch ein; technische Details sind 7 Tage embargoed. Dringend auf 4Analytics 5.0.2 aktualisieren (laeuft auf Joomla 3-6).\",\"note_en\":\"Two unauthenticated security flaws (CVE-2026-57833 + CVE-2026-58077) in ALL versions before 5.0.2 - an anonymous attacker needs no login. Vendor Weeblr rates both critical; technical details are under a 7-day embargo. Update to 4Analytics 5.0.2 urgently (runs
on Joomla 3-6).\",\"advisory\":\"https:\\/\\/weeblr.com\\/blog\\/critical-vulnerabilities-2026-07-15\",\"advisory_en\":\"https:\\/\\/weeblr.com\\/blog\\/critical-vulnerabilities-2026-07-15\"},{\"element\":\"com_quix\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Quix\",\"below\":\"6.2.1\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Unauthentifizierte SQL-Injection (Free UND Pro, alle Versionen vor 6.2.1 \\u2013 auch die 5.x-Reihe): ein anonymer Besucher kann die gesamte Datenbank auslesen (CVSS 8.7). HTProtects Mini-WAF blockt den Angriff bereits aktiv. Auf Quix 6.2.1 aktualisieren (Free erh\\u00e4lt 6.2.1 ebenfalls \\u00fcber die Update-Funktion).\",\"note_en\":\"Unauthenticated SQL injection (Free
AND Pro, all versions below 6.2.1 \\u2013 including the 5.x line): an anonymous visitor can read the entire database (CVSS 8.7). HTProtect\'s mini-WAF already actively blocks the attack. Update to Quix 6.2.1 (Free receives 6.2.1 too via the update function).\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/quix-sql-injection-disclosure\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/quix-sql-injection-disclosure\\/\"},{\"element\":\"com_joomcck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JoomCCK\",\"below\":\"6.4.1\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"Unauthentifizierte SQL-Injection (CVE-2026-49048, JoomCCK 6.x vor 6.4.1): der Front-End-Task \\u201eTag speichern\\/l\\u00f6schen\\\" pr\\u00fcfte weder Login noch Token und \\u00fcbernahm den Parameter \\u201etag\\\" ungefiltert in zwei SQL-Abfragen - ein anonymer Besucher konnte die Datenbank auslesen und ver\\u00e4ndern. HTProtects Mini-WAF blockt den unautorisierten Gast-Aufruf bereits aktiv. Dringend auf JoomCCK 6.4.1 aktualisi\",\"note_en\":\"Unauthenticated SQL injection (CVE-2026-49048, JoomCCK 6.x before 6.4.1): the front-end \\\"save\\/delete tag\\\" task checked neither login nor token
and took the \\\"tag\\\" parameter unfiltered into two SQL queries - an anonymous visitor could read
and modify the database. HTProtect\'s mini-WAF already actively blocks the unauthorized guest call. Update to JoomCCK 6.4.1 urgently.\",\"advisory\":\"https:\\/\\/github.com\\/JoomCoder-com\\/JoomCCK\\/releases#release-6.4.1\",\"advisory_en\":\"https:\\/\\/github.com\\/JoomCoder-com\\/JoomCCK\\/releases#release-6.4.1\"},{\"element\":\"com_chronoforms8\",\"type\":\"component\",\"folder\":\"\",\"name\":\"ChronoForms\",\"below\":\"8.0.53\",\"above\":\"8.0.0\",\"severity\":\"high\",\"note\":\"Unauthentifizierte gespeicherte XSS (CVE-2026-58148, ChronoForms 8.x vor 8.0.53): ein anonymer Besucher schleust \\u00fcber ein Formular-Feld JavaScript ein, das ungefiltert gespeichert und sp\\u00e4ter - z. B. beim Ansehen der Einsendungen im Backend - ausgef\\u00fchrt wird, bis hin zur \\u00dcbernahme der Admin-Sitzung (CVSS 8.7). Auf ChronoForms 8.0.53 aktualisieren.\",\"note_en\":\"Unauthenticated stored XSS (CVE-2026-58148, ChronoForms 8.x before 8.0.53): an anonymous visitor injects JavaScript via a form field that is stored unfiltered
and later executed - e.g. when viewing the submissions in the backend - up to takeover of the admin session (CVSS 8.7). Update to ChronoForms 8.0.53.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-58148\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-58148\"},{\"element\":\"com_jdownloads\",\"type\":\"component\",\"folder\":\"\",\"name\":\"jDownloads\",\"below\":\"4.1.6\",\"above\":\"4.1.0\",\"severity\":\"high\",\"note\":\"Unauthentifizierte Datei-Upload-L\\u00fccke (jDownloads 4.1.0-4.1.5): eine verwaiste Uploader-Datei (upload-handler.php) pr\\u00fcft weder Login noch Token und l\\u00e4sst einen anonymen Besucher beliebige Dateien - u. a. exe\\/msi\\/Archive - in einen Ordner der Site schreiben; auf manchen Servern bis zur Codeausf\\u00fchrung, sonst Malware-Hosting\\/Speicher-Flutung. HTProtects .htaccess-Schutzschild blockt den direkten \",\"note_en\":\"Unauthenticated file upload flaw (jDownloads 4.1.0-4.1.5): a leftover uploader file (upload-handler.php) checks neither login nor token
and lets an anonymous visitor write arbitrary files - incl. exe\\/msi\\/archives - into a folder
on the site; up to remote code execution
on some servers, otherwise malware hosting \\/ disk flooding. HTProtect\'s .htaccess shield already blocks direct access to the file \",\"advisory\":\"https:\\/\\/www.jdownloads.com\\/index.php\\/news\\/jdownloads-4-1-6-secure-update-released.html\",\"advisory_en\":\"https:\\/\\/www.jdownloads.com\\/index.php\\/news\\/jdownloads-4-1-6-secure-update-released.html\"},{\"element\":\"com_dpcalendar\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DPCalendar\",\"below\":\"10.11.2\",\"above\":\"9.0.0\",\"severity\":\"high\",\"note\":\"DPCalendar (Joomla 4.4-6, 9.0.0-10.11.1): unauthentifizierte Blind-SQL-Injection - der Autor-Filter filter_created_by (Frontend view=events) floss in skalarer Form ohne Integer-Cast in die Query (a.created_by IN ...); ein anonymer Besucher kann beliebige DB-Tabellen AUSLESEN (nichts \\u00e4ndern). Dringend auf 10.11.2 aktualisieren. HTProtects Mini-WAF blockt die Injektion bereits.\",\"note_en\":\"DPCalendar (Joomla 4.4-6, 9.0.0-10.11.1): unauthenticated blind SQL injection - the author filter filter_created_by (front-end view=events) flowed uncast (scalar form) into the query (a.created_by IN ...); an anonymous visitor can READ arbitrary DB tables (no writes). Update to 10.11.2 urgently. HTProtect mini-WAF already blocks the injection.\",\"advisory\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\",\"advisory_en\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\"},{\"element\":\"com_dpcalendar\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DPCalendar\",\"below\":\"8.19.4\",\"above\":\"8.18.0\",\"severity\":\"high\",\"note\":\"DPCalendar Joomla-3-Linie (8.x), 8.18.0-8.19.3: dieselbe unauth Blind-SQL-Injection \\u00fcber den Autor-Filter filter_created_by (skalar, ohne Integer-Cast, nur lesend). In 8.19.4 (Joomla-3-Fix) behoben. Auf 8.19.4 aktualisieren. HTProtects Mini-WAF blockt die Injektion bereits.\",\"note_en\":\"DPCalendar Joomla 3 line (8.x), 8.18.0-8.19.3: same unauth blind SQL injection via the author filter filter_created_by (scalar, no integer cast, read-only). Fixed in 8.19.4 (Joomla 3 fix). Update to 8.19.4. HTProtect mini-WAF already blocks the injection.\",\"advisory\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\",\"advisory_en\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\"},{\"element\":\"com_phocadownload\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Download\",\"below\":\"6.1.3\",\"above\":\"6.0.0\",\"severity\":\"high\",\"note\":\"Authentifizierter Datei-Upload -> RCE (Versionen 6.0 bis 6.1.2): ein eingeloggter Nutzer mit Zugriff auf die Upload-Funktion kann eine ausf\\u00fchrbare Datei (z. B. .php) hochladen und ausf\\u00fchren. In 6.1.3 (Security-Release) behoben - auf 6.1.3 oder neuer aktualisieren. HTProtects PHP-Schild verhindert die Ausf\\u00fchrung einer hochgeladenen PHP-Datei in den Upload-Ordnern bereits.\",\"note_en\":\"Authenticated file upload -> RCE (versions 6.0 to 6.1.2): a logged-in user with access to the upload feature can upload
and run an executable file (e.g. .php). Fixed in 6.1.3 (security release) - update to 6.1.3 or newer. The HTProtect PHP shield already prevents execution of an uploaded PHP file in the upload folders.\",\"advisory\":\"https:\\/\\/www.phoca.cz\\/news\\/1481-phoca-download-version-6-1-3-released-security-release\",\"advisory_en\":\"https:\\/\\/www.phoca.cz\\/news\\/1481-phoca-download-version-6-1-3-released-security-release\"},{\"element\":\"com_phocamaps\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Maps\",\"below\":\"6.1.0\",\"above\":\"5.0.0\",\"severity\":\"medium\",\"note\":\"CVE-2026-65763: reflektiertes XSS (5.0.0-6.0.4) durch unzureichende Eingabepr\\u00fcfung - ein Angreifer bringt einen Besucher \\u00fcber einen pr\\u00e4parierten Link dazu, eingeschleustes JavaScript auszuf\\u00fchren. Auf Phoca Maps 6.1.0 (Security-Release) oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-65763: reflected XSS (5.0.0-6.0.4) via improper input validation - an attacker lures a visitor with a crafted link to run injected JavaScript. Update to Phoca Maps 6.1.0 (security release) or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65763\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65763\"},{\"element\":\"com_phocaguestbook\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Guestbook\",\"below\":\"6.1.1\",\"above\":\"5.0.0\",\"severity\":\"medium\",\"note\":\"CVE-2026-65762: reflektiertes XSS (5.0.0-6.1.0) durch unzureichende Eingabepr\\u00fcfung - ein pr\\u00e4parierter Link f\\u00fchrt beim Besucher eingeschleustes JavaScript aus. Auf Phoca Guestbook 6.1.1 (Security-Release) oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-65762: reflected XSS (5.0.0-6.1.0) via improper input validation - a crafted link runs injected JavaScript in the visitor\'s browser. Update to Phoca Guestbook 6.1.1 (security release) or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65762\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65762\"},{\"element\":\"com_acym\",\"type\":\"component\",\"folder\":\"\",\"name\":\"AcyMailing 6+\",\"below\":\"10.11.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"AcyMailing Neuauflage (6+): CVE-2026-56292 unauthentifizierte SQL-Injection (6.0.0-10.11.0) - ein anonymer Angreifer liest beliebige DB-Tabellen inkl. Passwort-Hashes (CVSS 8.7). \\u00c4ltere L\\u00fccken: CVE-2023-28731 unauth Upload\\/RCE unter 8.3.0, CVE-2026-3614 Rechteausweitung 9.11.0-10.8.1. Dringend auf 10.11.1 aktualisieren.\",\"note_en\":\"AcyMailing new line (6+): CVE-2026-56292 unauthenticated SQL injection (6.0.0-10.11.0) - an anonymous attacker reads arbitrary DB tables incl. password hashes (CVSS 8.7). Older holes: CVE-2023-28731 unauth upload\\/RCE below 8.3.0, CVE-2026-3614 privilege escalation 9.11.0-10.8.1. Update to 10.11.1 urgently.\",\"advisory\":\"https:\\/\\/htprotect.org\\/acymailing\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/acymailing\"},{\"element\":\"com_acymailing\",\"type\":\"component\",\"folder\":\"\",\"name\":\"AcyMailing Classic\",\"below\":\"4.9.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"AcyMailing Classic (End-of-Life): \\u00e4ltere Versionen mit kritischen L\\u00fccken - unauthentifizierter Datei-Upload der 3.x-\\u00c4ra (RCE, z. B. 3.9.0) sowie Backend-SQL-Injection CVE-2015-7338 (in 4.9.5 behoben). Auf eine unterst\\u00fctzte AcyMailing-Version migrieren. (Die 5.x-Linie hat keine bekannte sehr kritische L\\u00fccke; CSV-Injection CVE-2018-9107 in 5.9.1-5.9.5 ist niedrig\\/client-seitig.)\",\"note_en\":\"AcyMailing Classic (end-of-life): older versions with critical holes - unauthenticated file upload of the 3.x era (RCE, e.g. 3.9.0)
and backend SQL injection CVE-2015-7338 (fixed in 4.9.5). Migrate to a supported AcyMailing version. (The 5.x line has no known very critical hole; CSV injection CVE-2018-9107 in 5.9.1-5.9.5 is low\\/client-side.)\",\"advisory\":\"https:\\/\\/htprotect.org\\/acymailing\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/acymailing\"},{\"element\":\"com_igallery\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Ignite Gallery\",\"below\":\"5.4.1\",\"above\":\"5.0.0\",\"severity\":\"high\",\"note\":\"Ignite Gallery 5.0.0 bis 5.4.0: Stored XSS (hoch) durch fehlendes Output-Escaping beim Hochladen\\/Bearbeiten von Bildern, dazu SSRF (ungefilterte Video-URL) und eine Rechteausweitung beim Download geschuetzter\\/unveroeffentlichter Bilder. Ausnutzbar von Nutzern MIT Upload-\\/Bearbeitungsrecht (Frontend oder Backend). Auf 5.4.1 oder neuer aktualisieren.\",\"note_en\":\"Ignite Gallery 5.0.0 to 5.4.0: stored XSS (high) via missing output escaping when uploading\\/editing images, plus SSRF (unfiltered video URL)
and a privilege escalation when downloading restricted\\/unpublished images. Exploitable by users WITH upload\\/edit permission (frontend or backend). Update to 5.4.1 or newer.\",\"advisory\":\"https:\\/\\/www.ignitegallery.com\\/documentation\\/changelog\",\"advisory_en\":\"https:\\/\\/www.ignitegallery.com\\/documentation\\/changelog\"},{\"element\":\"com_icagenda\",\"type\":\"component\",\"folder\":\"\",\"name\":\"iCagenda\",\"below\":\"4.0.8\",\"above\":\"4.0.0\",\"severity\":\"critical\",\"note\":\"CVE-2026-48939 (4.x-Linie 4.0.0-4.0.7): das Event-Formular (task=submit.submit) pr\\u00fcft nur das CSRF-Token, keine Zugriffsrechte - anonymer Datei-Upload. Voller RCE nur auf Joomla 6 (Core blockt .php nicht mehr); auf Joomla <=5 mildert der Core-Filter, die Zugriffsl\\u00fccke bleibt. Dringend auf 4.0.8 aktualisieren. HTProtects Dateischild verhindert die Ausf\\u00fchrung bereits.\",\"note_en\":\"CVE-2026-48939 (4.x line 4.0.0-4.0.7): the event form (task=submit.submit) checks only the CSRF token, no access rights - anonymous file upload. Full RCE only
on Joomla 6 (core no longer blocks .php);
on Joomla <=5 the core filter mitigates but the access flaw remains. Update to 4.0.8 urgently. The HTProtect file shield already prevents execution.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/icagenda-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/icagenda-sicherheitsluecke-joomla\"},{\"element\":\"com_icagenda\",\"type\":\"component\",\"folder\":\"\",\"name\":\"iCagenda\",\"below\":\"3.9.15\",\"above\":\"3.2.1\",\"severity\":\"critical\",\"note\":\"CVE-2026-48939, 3.x-Linie 3.2.1-3.9.14: dieselbe Zugriffsl\\u00fccke im Event-Formular (task=submit.submit, keine Rechtepr\\u00fcfung, anonymer Datei-Upload). In 3.9.15 (Security-Backport f\\u00fcr Joomla 3) behoben. Dringend auf 3.9.15 aktualisieren. HTProtects Dateischild verhindert die Ausf\\u00fchrung bereits. (Voller RCE v. a. auf Joomla 6.)\",\"note_en\":\"CVE-2026-48939, 3.x line 3.2.1-3.9.14: same access-control flaw in the event form (task=submit.submit, no permission check, anonymous file upload). Fixed in 3.9.15 (security backport for Joomla 3). Update to 3.9.15 urgently. The HTProtect file shield already prevents execution. (Full RCE mainly
on Joomla 6.)\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/icagenda-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/icagenda-sicherheitsluecke-joomla\"},{\"element\":\"com_sppagebuilder\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP Page Builder\",\"below\":\"6.7.1\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"Unauthentifizierte SQL-Injection (CVE-2026-65766) bis Version 6.7.0: ein anonymer Besucher liest \\u00fcber einen ungefilterten Parameter (direction) im Dynamic-Content-Endpunkt beliebige Datenbank-Tabellen aus - bis zu Benutzerkonten, Passwort-Hashes und dem Seiten-Geheimnis (CVSS 8.7). Dazu ein offenes Mail-Relay (CVE-2026-65877): Angreifer verschicken \\u00fcber die Kontaktformular-Addons beliebige E-Mai\",\"note_en\":\"Unauthenticated SQL injection (CVE-2026-65766) up to version 6.7.0: via an unfiltered parameter (direction) in the Dynamic Content endpoint an anonymous visitor can read arbitrary database tables - down to user accounts, password hashes
and the site secret (CVSS 8.7). Plus an open mail relay (CVE-2026-65877): attackers send arbitrary emails with a spoofed sender through the contact-form addons. Up\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/sp-page-builder-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/sp-page-builder-sicherheitsluecke-joomla\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.6\",\"above\":\"3.5.0\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) bis 3.5.10: ein Front-End-Upload-Endpunkt (zum Hinzuf\\u00fcgen von Bildern) pr\\u00fcfte nur das CSRF-Token, aber keine Zugriffsrechte und keinen Dateityp - ein nicht eingeloggter Angreifer konnte eine beliebige Datei (z. B. PHP-Shell) in einen frei w\\u00e4hlbaren Ordner hochladen und ausf\\u00fchren (Remote Code Execution). Dringend auf 3.6.0 aktualisieren. (HTProtects generischer Upload-Sch\",\"note_en\":\"Critical flaw (RCE) up to 3.5.10: a front-end upload endpoint (for adding images) only verified the CSRF token but no access rights
and no file type - an unauthenticated attacker could upload an arbitrary file (e.g. a PHP shell) into a freely chosen folder
and execute it (remote code execution). Update to 3.6.0 urgently. (The HTProtect generic upload protection already blocks the unauthenticated u\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.4.10\",\"above\":\"3.2.0\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) in der Joomla-4-Linie unter 3.4.10: unauthentifizierter Datei-Upload \\u00fcber einen Front-End-Endpunkt (nur CSRF-Token, keine Zugriffs-\\/Typpr\\u00fcfung) - beliebige Datei in frei w\\u00e4hlbaren Ordner hochladbar und ausf\\u00fchrbar. In 3.4.10 (Backport) behoben. Dringend aktualisieren. (HTProtects generischer Upload-Schutz blockt den unauthentifizierten Upload bereits; das Dateischild verh\",\"note_en\":\"Critical flaw (RCE) in the Joomla 4 line below 3.4.10: unauthenticated file upload via a front-end endpoint (CSRF token only, no access\\/type check) - arbitrary file uploadable into a freely chosen folder
and executable. Fixed in 3.4.10 (backport). Update urgently. (The HTProtect generic upload protection already blocks the unauthenticated upload; the file shield additionally prevents execution.)\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.1.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) in der Joomla-3-Linie unter 3.1.1: unauthentifizierter Datei-Upload \\u00fcber einen Front-End-Endpunkt (nur CSRF-Token, keine Zugriffs-\\/Typpr\\u00fcfung) - beliebige Datei in frei w\\u00e4hlbaren Ordner hochladbar und ausf\\u00fchrbar. In 3.1.1 (Backport f\\u00fcr Joomla 3) behoben. Dringend aktualisieren. (HTProtects generischer Upload-Schutz blockt den unauthentifizierten Upload bereits; das Date\",\"note_en\":\"Critical flaw (RCE) in the Joomla 3 line below 3.1.1: unauthenticated file upload via a front-end endpoint (CSRF token only, no access\\/type check) - arbitrary file uploadable into a freely chosen folder
and executable. Fixed in 3.1.1 (backport for Joomla 3). Update urgently. (The HTProtect generic upload protection already blocks the unauthenticated upload; the file shield additionally prevents ex\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_eventbooking\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Events Booking\",\"below\":\"5.8.1\",\"above\":\"5.0\",\"severity\":\"medium\",\"note\":\"Zwei Sicherheitsl\\u00fccken ohne Anmeldung in allen Versionen der 5er-Reihe vor 5.8.1: Erstens konnte jeder anonyme Besucher \\u00fcber die Datei-Upload-Funktion des Anmeldeformulars Dateien auf dem Server ablegen - ohne Konto, ohne Anmeldung und ohne Sicherheitstoken; die Funktion war ab Werk in jeder Installation aktiv. Die abgelegten Dateien lie\\u00dfen sich anschlie\\u00dfend unter einem vorhersehbaren Namen wi\",\"note_en\":\"Two unauthenticated security flaws in all versions of the 5.x line below 5.8.1: First, any anonymous visitor could place files
on the server through the file upload of the registration form - no account, no login, no security token; the feature was enabled by default in every installation. The uploaded files could then be retrieved again under a predictable name. Program files were not allowed in \",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/events-booking-unauthenticated-upload-user-enumeration\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/events-booking-unauthenticated-upload-user-enumeration\\/\"},{\"element\":\"com_djclassifieds\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DJ-Classifieds\",\"below\":\"3.11.2\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Schwerwiegende L\\u00fccke in allen Versionen bis einschlie\\u00dflich 3.11.1: Die Funktion zum Hochladen von Anzeigenbildern nahm Dateien entgegen, ohne dass eine Anmeldung n\\u00f6tig war und ohne die \\u00fcblichen Sicherheitspr\\u00fcfungen. Angreifer konnten dadurch eine Schaddatei auf der Website ablegen und im ung\\u00fcnstigen Fall die Kontrolle \\u00fcber die gesamte Seite \\u00fcbernehmen. Die L\\u00fccke wurde bereits aktiv ausgen\",\"note_en\":\"Serious flaw in all versions up to
and including 3.11.1: the image upload used for classified ads accepted files without requiring a login
and without the usual security checks. This allowed attackers to place a malicious file
on the website
and, in the worst
case, take control of the entire site. The flaw was already being actively exploited before a fix was available. Update to version 3.11.2 or\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/dj-classifieds-unauthenticated-file-upload\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/dj-classifieds-unauthenticated-file-upload\\/\"},{\"element\":\"com_gridbox\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Gridbox\",\"below\":\"2.20.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Balbooa hat in zwei Schritten reagiert: 2.20.1 (20.07.2026) schloss eine kritische Anmelde-L\\u00fccke (CVE-2026-61425), blieb aber unvollst\\u00e4ndig. Erst 2.20.2 (29.07.2026) behebt - laut Hersteller in allen Versionen bis einschlie\\u00dflich 2.20.1 - unbefugten Dateizugriff (Lesen und Schreiben), das rekursive L\\u00f6schen ganzer Ordner, mehrere SQL-Einschleusungen, weitere Umgehungen der Rechtepr\\u00fcfung und Inf\",\"note_en\":\"Balbooa responded in two steps: 2.20.1 (20 Jul 2026) closed a critical authentication flaw (CVE-2026-61425) but was incomplete. Only 2.20.2 (29 Jul 2026) fixes - across all versions up to
and including 2.20.1, per the vendor - unauthorized file access (read
and write), recursive deletion of whole directories, multiple SQL injections, further authorization-check bypasses
and information disclosure.\",\"advisory\":\"https:\\/\\/www.balbooa.com\\/blog\\/gridbox\\/gridbox-2-20-2-security-release\",\"advisory_en\":\"https:\\/\\/www.balbooa.com\\/blog\\/gridbox\\/gridbox-2-20-2-security-release\"}],\"php_min\":\"8.1\",\"fetched\":\"2026-08-01 01:42:25\",\"fetched_ts\":1785615665,\"etag\":\"\\\"6a6d343c-f907\\\"\",\"modified\":\"Fri, 31 Jul 2026 23:48:12 GMT\",\"joomla_latest\":{\"3\":\"3.10.12\",\"4\":\"4.4.14\",\"5\":\"5.4.7\",\"6\":\"6.1.2\"},\"joomla_latest_ts\":1785590511,\"joomla_latest_try\":1785590511},\"htp_malware\":{\"schema\":1,\"version\":\"2026-07-29.671bb5\",\"sigs\":[{\"id\":\"backdoor-prepend-sshkey\",\"all\":[\"auto_prepend_file\",\"authorized_keys\"]},{\"id\":\"cred-stealer-ctfaudit\",\"any\":[\"x-ctf-audit\",\"jlib_audit_gid\"]},{\"id\":\"upload-shell-form\",\"all\":[\"move_uploaded_file\",\"check directory permissions\"]},{\"id\":\"sppb-iconfont-shell\",\"any\":[\"sppbwhoami\"]},{\"id\":\"remote-eval-loader\",\"all\":[\"eval(\\\"?>\\\"\"],\"any\":[\"fetchcontentfromurl\",\"file_get_contents(\\\"http\",\"file_get_contents(\'http\"]},{\"id\":\"seo-doorway-slot\",\"any\":[\"slot gacor\",\"situs slot gacor\"]},{\"id\":\"filemanager-backdoor-data\",\"all\":[\"<?php exit;?>{\",\"\\\"groupinfo\\\"\",\"\\\"sizemax\\\"\"]},{\"id\":\"encrypted-eval-openssl\",\"all\":[\"openssl_raw_data\",\"aes-256-cbc\"],\"not\":[\"openssl_decrypt\",\"openssl_encrypt\"]},{\"id\":\"0xnix-split-encrypted\",\"all\":[\"0xnix encrypted code\"]},{\"id\":\"upload-shell-devco1\",\"all\":[\"move_uploaded_file\",\"devco1\"]},{\"id\":\"upload-shell-uname-form\",\"all\":[\"move_uploaded_file\",\"php_uname\",\"multipart\\/form-data\"]},{\"id\":\"hacktool-adminer\",\"all\":[\"adminer_errors\",\"idf_unescape\"]},{\"id\":\"webshell-range-obfuscator\",\"all\":[\"\\\"r\\\".\\\"a\\\".\\\"n\\\".\\\"g\\\".\\\"e\\\"\",\"eval\"]},{\"id\":\"webshell-md5quad-gate\",\"all\":[\"md5(md5(md5(md5(\",\"eval\"]},{\"id\":\"remote-loader-stream-include\",\"any\":[\"include stream_get_meta_data\",\"require stream_get_meta_data\",\"include(stream_get_meta_data\",\"require(stream_get_meta_data\"]},{\"id\":\"webshell-dual-uploader\",\"all\":[\"remote_url\",\"name=\\\"_upl\\\"\",\"name=\\\"_remote\\\"\"]},{\"id\":\"webshell-comment-obfuscator\",\"all\":[\"-*\\/\\/\\/\",\"\\\"~\\\"\"]},{\"id\":\"eval-openssl-shell\",\"label\":\"eval(openssl_decrypt) webshell\",\"all\":[\"eval(openssl_decrypt(\"]},{\"id\":\"dropper-drivergenius-c2\",\"label\":\"Remote-fetch dropper (drivergenius C2)\",\"all\":[\"drivergenius.it.com\"]},{\"id\":\"dropper-backdate-disguise\",\"label\":\"Remote-fetch dropper (mtime-forge + disguise)\",\"all\":[\"getreferencefiletime\",\"generatefilename\"]},{\"id\":\"js-inject-fake-cleaned\",\"label\":\"JS injection w\\/ fake \\\"cleaned\\/safe\\\" comment\",\"all\":[\"artifacts of previous malicious infection\",\"dangerous code has been removed\"]},{\"id\":\"linkforge-seo-injector\",\"label\":\"LinkForge SEO backlink injector\",\"all\":[\"linkforge.cc\"]},{\"id\":\"seo-doorway-cloak\",\"label\":\"SEO cloaking doorway (Thai gambling, fake sitemap)\",\"all\":[\"output_sitemap_page\",\"is_from_google\",\"send_404_and_exit\"]},{\"id\":\"helix-ultimate-xss\",\"label\":\"Helix Ultimate mega-menu XSS campaign\",\"any\":[\"xss.report\",\"_hu_inject\",\"_huinject\",\"sessionstorage._hxd\"]},{\"id\":\"gsocket-c2\",\"label\":\"gsocket reverse-shell C2 marker\",\"any\":[\"gs_args\"]},{\"id\":\"cloak-engine-thiscitze\",\"label\":\"thiscitze SEO cloaking engine\",\"all\":[\"thiscitze\"]},{\"id\":\"cloak-doorway-jsurl-jumpurl\",\"label\":\"Thai gambling SEO cloaking\\/doorway injector\",\"all\":[\"$js_url\",\"$jump_url\"]},{\"id\":\"cn-aes-loader\",\"label\":\"AES-decrypt + gzinflate eval loader\",\"all\":[\"openssl_decrypt\",\"gzinflate\",\"eval(\\\"?>\\\"\"]},{\"id\":\"cn-loader-tag\",\"label\":\"Chinese \'PHP code security loader\' tag\",\"all\":[\"php\\u4ee3\\u7801\\u5b89\\u5168\\u52a0\\u8f7d\\u5668\"]},{\"id\":\"menu-api-filemanager\",\"label\":\"MENU_API file-manager webshell\",\"all\":[\"menu_api_password\"]},{\"id\":\"remote-eval-curl\",\"label\":\"curl remote-fetch eval loader\",\"all\":[\"eval(\\\"?>\\\"\",\"curl_exec\"]},{\"id\":\"bujang-c2\",\"label\":\"Remote-fetch loader (bujang.online C2)\",\"all\":[\"bujang.online\"]},{\"id\":\"tinyfilemanager-tool\",\"label\":\"Tiny File Manager (webshell-capable file manager)\",\"all\":[\"tinyfilemanager\"]}],\"names\":[{\"id\":\"probe-d1337\",\"m\":[\"_d1337_\"],\"label\":\"d1337 write-access probe \\/ dropper marker\"},{\"id\":\"probe-write-test\",\"m\":[\"_probe_\"],\"label\":\"generic write-access probe marker (_probe_)\"}],\"scan_ext\":[],\"ack\":[\"6608daed700e0afc330788b2a272ca8d\",\"67b5f9a00c7aabf34261c715aeeaadba\",\"9812b693256a0c306cc53368559c7a4b\",\"ec96a3bed6681af996fd37f0818cba6b\",\"abfe3b7513994ae6ac2f33129b5f6e7b\",\"fb2e76c5ebafc2b8ea82e0d35d45fa02\",\"2ec54ce00420cd41dfae5abedc9edcb7\",\"02c1a767857c55d31cae7277bc43bac2\",\"573a5e7374be2925911b552d485a28f3\",\"cdf24443c39d943f8750d4a4420e6581\",\"99af93b919c5b6bc14a82382c39010ec\",\"55e704bb88a8f9ab0d756976c527516b\",\"981b4f5e07bf9cd1249d60d659e4ef93\",\"87d978102ed075a8e58074a0d3595c30\",\"85648deb8324a11400ecaebcfd04ae16\",\"323707d28051b4cbf161420f5f1bb499\",\"19104a261abbdffe7cd1713949b286cf\",\"a72013015988ad7d978ce9841a9668dd\",\"a8af9b93d27c774601e1d8a902145bd7\",\"82c8de717e67a620ca503a1a01a7d909\",\"a8192a3cf6279862054cb3092dad82bf\",\"eae8beb708347cfe54bf87506b572f41\",\"5db6f4cdd20dfee86e05110a2276d748\",\"872e97edc1d4247d2ed86d35f468ff88\",\"da9c67c9b7be2d5a7eb9113d76119abc\",\"d0c5a881e845f93a72e1450259de0d33\",\"ea531694f501221b61a324d3754da603\",\"b8333a512d949684c91c9dd907f9cb0c\",\"2c57aea21d161fe5761ffab0abff8228\",\"93117860cd06939707a4ff1797bebb40\",\"7f58961ebcc0db81b16c2d16072fb084\",\"760423f79cedc17e78df95505e93f0c7\",\"d8b0c0f2faf44495f7954fe826720bad\",\"b9b6b8553113e745ebef3251b5d223b9\",\"3e5d03ecb5de8ab2ff1790d7b78bee24\",\"0cd3f898084fe66b062ab5162d2b370c\",\"deb26b6603b6edd8381f6c77fc53cace\",\"0855cf0d6a33b86a8506aeeb769e4343\",\"bcfa5def6057812cba39996c13c1feb3\",\"b719915e7d46c753fe4aeb7a6b8e7fea\",\"913459ac4f3b49356595a341f9b2ac03\"],\"community\":0,\"fp\":[{\"all\":[\"easycalccheckplus\"],\"only\":[\"rce\"],\"id\":\"ecc-plus-doc-rce\"},{\"all\":[\"phpoffice\\\\phpspreadsheet\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"phpspreadsheet-lib\"},{\"any\":[\"cp_errordocument\",\"status-reason\"],\"not\":[\"<!--#exec\",\"<?\"],\"only\":[\"shtml\"],\"id\":\"plesk-error-shtml\"},{\"all\":[\"gumlet\",\"data:\\/\\/application\\/octet-stream\"],\"only\":[\"wrapper\"],\"id\":\"gumlet-imageresize-datawrapper\"},{\"all\":[\"data:\\/\\/image\",\"exif_read_data\"],\"only\":[\"wrapper\"],\"id\":\"exif-data-wrapper\"},{\"all\":[\"phpoffice\\\\phpword\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"phpword-lib\"},{\"all\":[\"box\\\\spout\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"box-spout-lib\"},{\"all\":[\"sarciszewski\\\\phpfuture\"],\"only\":[\"wrapper\"],\"id\":\"php-future-lib\"},{\"all\":[\"baformsmodelform\"],\"only\":[\"feed:upload-shell-uname-form\"],\"id\":\"fp-baforms-model\"},{\"all\":[\"quixnxt\"],\"only\":[\"goto\"],\"id\":\"fp-quix-goto\"},{\"all\":[\"varexporter\"],\"only\":[\"goto\"],\"id\":\"fp-symfony-varexporter-goto\"},{\"all\":[\"valorapps.com\"],\"only\":[\"idxbuild\"],\"id\":\"fp-easyfolderlisting-changelog\"},{\"all\":[\"matomo.org\"],\"only\":[\"rce\"],\"id\":\"fp-matomo-rce\"},{\"all\":[\"namespace tracy\"],\"only\":[\"phtml\"],\"id\":\"fp-tracy-phtml\"},{\"all\":[\"guzzlehttp\",\"requestfsm\"],\"only\":[\"goto\"],\"id\":\"fp-guzzle-requestfsm\"},{\"all\":[\"siteguarding.com\",\"siteguarding_server_ip1\"],\"only\":[\"feed:upload-shell-uname-form\"],\"id\":\"fp-siteguarding-agent\"},{\"all\":[\"muruguard\"],\"only\":[\"feed:helix-ultimate-xss\"],\"id\":\"fp-muruguard-scanner\"},{\"all\":[\"<svg\"],\"not\":[\"<script\",\"<?php\",\"<?=\",\"onload=\",\"onerror=\",\"onmouseover=\",\"onclick=\",\"onfocus=\",\"javascript:\",\"<foreignobject\"],\"only\":[\"tmp_exec\"],\"id\":\"fp-benign-svg-tmp\"}],\"seo\":{\"weights\":[],\"keywords\":[],\"sigs\":[]},\"recall\":[],\"fetched\":\"2026-07-31 00:02:41\",\"fetched_ts\":1785610638,\"etag\":\"\\\"6a6b92d9-1e99\\\"\",\"modified\":\"Thu, 30 Jul 2026 18:07:21 GMT\"},\"htp_incidents\":[]}'
WHERE `type` = 'component'
AND `element` = 'com_htprotect'
VERKLAREN niet mogelijk voor zoekopdracht: UPDATE `hmclx_extensions`
SET `params` = '{\"htp_shield\":{\"site_path\":\"\",\"sef_rules\":1,\"api_router\":1,\"api_mode\":\"route\",\"fastcgi_auth\":1,\"apache_options\":1,\"follow_symlink\":0,\"force_https\":1,\"www_mode\":0,\"canonical_host\":\"\",\"h_frame\":1,\"h_nosniff\":1,\"h_referrer\":\"strict-origin-when-cross-origin\",\"h_poweredby\":1,\"h_hsts\":0,\"h_hsts_sub\":0,\"h_coop\":0,\"h_permissions\":0,\"f_query\":1,\"f_rfi\":1,\"f_methods\":1,\"f_wpnoise\":1,\"htaccess_external\":0,\"shield_autoheal\":1,\"shield_autoheal_last\":0,\"mig_selfon_2415\":1,\"guard_dismissed\":0,\"x_shield\":1,\"x_sigs_off\":[],\"defs_version\":\"2026-07-15.9ac386\",\"mal_whitelist\":[],\"u_harden\":1,\"u_dirs\":[\"images\",\"media\"],\"emergency_lock\":0,\"notify_email\":\"pch.info@dubbelbit.nl\",\"notify_reminder_days\":14,\"unsub_secret\":\"knIOkiU01E3ceU0YZZ8ARjTQkWuTbqXAfktb1qjg6K0\",\"unsub_base\":\"https:\\/\\/www.efitec.nl\\/\",\"site_fp\":\"6d83c72d155aaa19f87ab9edd8cf222657b5b548\",\"swarm_contrib_id\":\"\",\"swarm_acked\":[],\"watch_manifest\":{\".htaccess\":\"dcb97f95087f2bdb336d0ffdcc300371ca6c4c51\",\"administrator\\/.htaccess\":\"2a00152a7d76a1d4a9444edf477c7404821a8b08\",\"images\\/.htaccess\":\"69714eb0929213f686d66baa144fceefbb395f8f\",\"media\\/.htaccess\":\"69714eb0929213f686d66baa144fceefbb395f8f\"},\"core_manifest\":{\"index.php\":\"2f1b60fc565276ae146bea9aaeadec93fb4dc87c\",\"administrator\\/index.php\":\"7078c5d7b2181900c509c93302f324e2dae228bf\"},\"core_jversion\":\"3.10.12\",\"accounts_watch\":1,\"account_baseline\":{\"613\":{\"id\":613,\"username\":\"admin\",\"email\":\"pch.info@dubbelbit.nl\",\"phash\":\"6300584d05e69c7f07ba2fb51a2f5ade41aeedd4\",\"block\":0,\"lastvisit\":\"2026-07-15 10:54:36\",\"pneeds\":0},\"800\":{\"id\":800,\"username\":\"dubbelbit\",\"email\":\"info@dubbelbit.nl\",\"phash\":\"081a5bae87c5a349a57ac9416a5157be4b8f95d5\",\"block\":0,\"lastvisit\":\"2025-11-06 17:15:16\",\"pneeds\":0}},\"admin_whitelist\":[],\"helix_ignore\":[],\"seo_watch\":1,\"compat_guard\":1,\"seo_cloaking_auto\":0,\"seo_whitelist\":[],\"seo_topic_ack\":[],\"seo_baseline\":{\"title\":\"Home\",\"out_domains\":{\"www.facebook.com\":1,\"nl.pinterest.com\":1,\"www.youtube.com\":1,\"www.s-bb.nl\":1,\"nieuw.efitec.nl\":1,\"xdebug.org\":1},\"shingles\":{\"511079512\":1,\"2918310184\":1,\"155886152\":1,\"3160688592\":1,\"3485062088\":1,\"585239104\":1,\"3828873704\":1,\"4087449296\":1,\"3631890208\":1,\"2453473432\":1,\"352088384\":1,\"1507055824\":1,\"1387258184\":1,\"96078016\":1,\"4120744744\":1,\"884599352\":1,\"148068952\":1,\"2322729328\":1,\"1647395640\":1,\"550572240\":1,\"2804985368\":1,\"2665301464\":1,\"3371643872\":1,\"1999195856\":1,\"412108984\":1,\"3675484672\":1,\"2196848680\":1,\"2599037872\":1,\"4081499304\":1,\"187337984\":1,\"362962264\":1,\"2094558736\":1,\"2787016200\":1,\"1792673952\":1,\"3358772584\":1,\"3190343216\":1,\"2235320368\":1,\"4225413856\":1,\"148784336\":1,\"4133289600\":1,\"1990767144\":1,\"265081816\":1,\"1454988472\":1,\"3545206312\":1,\"2836836760\":1,\"1552018832\":1,\"344452216\":1,\"461581872\":1,\"202494824\":1,\"3735037840\":1,\"3332537384\":1,\"2554787144\":1,\"746144872\":1,\"1848356288\":1,\"3951814824\":1,\"1464161728\":1,\"982788704\":1,\"3748426760\":1,\"136372440\":1,\"3214585776\":1,\"1332842344\":1,\"1366336928\":1,\"754226368\":1,\"1993946344\":1,\"140539032\":1,\"3458701480\":1,\"1779788808\":1,\"829495128\":1,\"258726864\":1,\"2313381704\":1,\"506576576\":1,\"682230128\":1,\"2799752896\":1,\"1200023392\":1,\"1387821168\":1,\"3867735952\":1,\"235572904\":1,\"211001480\":1,\"1209613064\":1,\"1950179312\":1,\"39928272\":1,\"2520740096\":1,\"810676984\":1,\"1550852192\":1,\"3946537872\":1,\"1061088320\":1,\"924937024\":1,\"2981285080\":1,\"4214313248\":1,\"2706907200\":1,\"4109595712\":1,\"2467453096\":1,\"1925217168\":1,\"254204696\":1,\"2797136096\":1,\"3557110600\":1,\"4041208904\":1,\"1327249520\":1,\"1607673584\":1,\"4007425464\":1,\"2632851624\":1,\"3330990656\":1,\"2693581640\":1,\"689915416\":1,\"4066896848\":1,\"480467872\":1,\"3008275536\":1,\"3101468488\":1,\"172199312\":1,\"650342624\":1,\"2553018880\":1,\"2609132040\":1,\"2991890336\":1,\"3462925544\":1,\"2964742568\":1,\"357174032\":1,\"1561660688\":1,\"1048480240\":1,\"1489547928\":1,\"208422712\":1,\"3778160000\":1,\"3789275216\":1,\"2776431456\":1,\"507422944\":1,\"4101744904\":1,\"942566752\":1,\"3196827536\":1,\"648166736\":1,\"1094268640\":1,\"1260128512\":1,\"3590796976\":1,\"1273715136\":1,\"4239054088\":1,\"1559046784\":1,\"4007417480\":1,\"7730296\":1,\"1458451704\":1,\"2911589176\":1,\"454621680\":1,\"1251844592\":1,\"4015838272\":1,\"1300147528\":1,\"1236487296\":1,\"3294019280\":1,\"4123225216\":1,\"670221008\":1,\"2571777288\":1,\"3627078176\":1,\"293222816\":1,\"281163600\":1,\"2508087208\":1,\"3543193024\":1,\"1915969656\":1,\"717056536\":1,\"848595304\":1,\"3107900104\":1,\"2589595704\":1,\"2034508136\":1,\"1977429088\":1,\"2584638584\":1,\"2493542936\":1,\"1158834928\":1,\"1531644320\":1,\"4102387360\":1,\"39764600\":1,\"4261163824\":1,\"1123389784\":1,\"2094010560\":1,\"1856123928\":1,\"376102376\":1,\"4096007544\":1,\"2256249280\":1,\"1618392856\":1,\"2709313920\":1,\"444641888\":1,\"3013023016\":1,\"4217705304\":1,\"2214186752\":1,\"716719120\":1,\"1972556728\":1,\"2438508112\":1,\"1820085032\":1,\"1223539912\":1,\"2846665840\":1,\"933003528\":1,\"2230427152\":1,\"1208455864\":1,\"2025534160\":1,\"1408784776\":1,\"2685059296\":1,\"3489792648\":1,\"1615724560\":1,\"8044840\":1,\"2316854528\":1,\"2550915448\":1,\"1211668720\":1,\"1935561680\":1,\"1828019016\":1,\"1827743704\":1,\"1337666672\":1,\"1911606592\":1,\"3178569384\":1,\"2552993816\":1,\"2123798152\":1,\"3761658400\":1,\"548688272\":1,\"2129684000\":1,\"4124423392\":1,\"1153004272\":1,\"796890520\":1,\"1247028480\":1,\"958748368\":1,\"1744512424\":1,\"647816080\":1,\"743882928\":1,\"3084540200\":1,\"3651199344\":1,\"109843936\":1,\"3303788176\":1,\"3393712720\":1,\"2772452800\":1,\"1345583752\":1,\"4138023008\":1,\"1630734352\":1,\"1587613576\":1,\"1950652592\":1,\"2777296976\":1,\"2621186584\":1,\"36106456\":1,\"2825573424\":1,\"303059736\":1,\"955024752\":1,\"4174757896\":1,\"335870296\":1,\"947878136\":1,\"885775072\":1,\"2836090264\":1,\"1479167544\":1,\"3195444184\":1,\"1373515616\":1,\"2703441304\":1,\"2999798000\":1,\"807202496\":1,\"2139078408\":1,\"3679148440\":1,\"4128820280\":1,\"4051291288\":1,\"524040760\":1,\"3226643448\":1,\"3914545768\":1,\"3485632672\":1,\"1455493656\":1,\"3040222736\":1,\"1738075592\":1,\"3987514200\":1,\"428036792\":1,\"2710735120\":1,\"3436957576\":1,\"3230827720\":1,\"1002378832\":1,\"477165832\":1,\"1378722152\":1,\"2798472384\":1,\"272556984\":1,\"351010464\":1,\"2168780672\":1,\"1806222752\":1,\"3716151024\":1,\"209155304\":1,\"2826036216\":1,\"420540632\":1,\"4203005848\":1,\"957468880\":1,\"1728849744\":1,\"4015778440\":1,\"1216866856\":1,\"4007963960\":1,\"3846677624\":1,\"3656753424\":1,\"75803256\":1,\"600705112\":1,\"1859028960\":1,\"2694091560\":1,\"2607914576\":1,\"2834052552\":1,\"3439897368\":1,\"2144818552\":1,\"3130333816\":1,\"3591606896\":1,\"1894249248\":1,\"4188555200\":1,\"245520800\":1,\"1682089672\":1,\"9149544\":1,\"3226699984\":1,\"1372800744\":1,\"2964205104\":1,\"722285192\":1,\"2322851088\":1,\"2139649696\":1,\"603889336\":1,\"3640799032\":1,\"1116378504\":1,\"3895415872\":1,\"1253935208\":1,\"528756504\":1,\"2284709784\":1,\"802473640\":1,\"3733678920\":1,\"361847392\":1,\"1232831160\":1,\"144058216\":1,\"1338885880\":1,\"992984272\":1,\"3773773072\":1,\"4182600\":1,\"2502992360\":1,\"4070217592\":1,\"547683160\":1,\"3290051432\":1,\"79724832\":1,\"821879880\":1,\"3181784208\":1,\"2105835160\":1,\"1048475128\":1,\"1530568368\":1,\"3978930832\":1,\"4141876912\":1,\"3134899488\":1,\"1235858440\":1,\"810201200\":1,\"3515040152\":1,\"2863190304\":1,\"1420257944\":1,\"798171424\":1,\"3843014608\":1,\"610676112\":1,\"1833740312\":1,\"3925377248\":1,\"2006124312\":1,\"3781864704\":1,\"3031336392\":1,\"4137422488\":1,\"3039953848\":1,\"1385104704\":1,\"4245224744\":1,\"4290332968\":1,\"2274655504\":1,\"1645581528\":1,\"2669455816\":1,\"3722712864\":1,\"1646278032\":1,\"2080430464\":1,\"1286501976\":1,\"1591713568\":1,\"1088809128\":1,\"3634194248\":1,\"3615937792\":1,\"3089178208\":1,\"3235297640\":1,\"1552428824\":1,\"1558271616\":1,\"2721862208\":1,\"1872388720\":1,\"1925908336\":1,\"1739818640\":1,\"1067862528\":1,\"4176326200\":1,\"1295895024\":1,\"1416323816\":1,\"252019184\":1,\"673687856\":1,\"1020035096\":1,\"1477984416\":1,\"798794864\":1,\"3895830512\":1,\"3877253568\":1,\"3725099576\":1,\"2100351152\":1,\"2474987096\":1,\"73942424\":1,\"13272208\":1,\"1943482168\":1,\"3977611416\":1,\"1547675656\":1,\"1718305248\":1,\"1732106904\":1,\"1643112200\":1,\"1345094056\":1,\"2907109104\":1,\"1613823168\":1,\"1646322024\":1},\"redirect_to\":\"\",\"ts\":1785610640},\"seo_overview_ts\":1785610637,\"seo_overview_finding\":[],\"core_overview_ts\":1784128054,\"core_overview_finding\":[],\"plugin_initialized\":1,\"quickicon_initialized\":1,\"autosecure\":0,\"autosecure_last\":0,\"tmp_autoclean\":0,\"tmp_keep\":[],\"autoupdate_notify\":0,\"autoupdate_ext\":1,\"autoupdate_all\":0,\"autoupdate_self\":1,\"autoupdate_manual\":0,\"autoupdate_mail_success\":0,\"autoupdate_include\":[],\"autoupdate_keep\":1,\"autoupdate_interval\":86400,\"autoupdate_schedule\":\"daily\",\"autoupdate_hour\":21,\"autoupdate_weekday\":5,\"autoupdate_grace\":3,\"autoupdate_malscan\":1,\"autoupdate_skip_major\":0,\"keep_update_sites\":1,\"keep_update_sites_except\":[],\"s_php\":1,\"s_types\":1,\"s_ext\":\"7z,avif,bmp,br,css,csv,doc,docx,eot,geojson,gif,gml,gpx,gz,htm,html,ico,ics,jp2,jpe,jpeg,jpg,js,json,kml,kmz,m4a,m4v,map,mjs,mov,mp3,mp4,mpeg,mpg,odp,ods,odt,oga,ogg,ogv,opus,otf,pdf,png,ppt,pptx,rar,rtf,svg,svgz,tif,tiff,ttf,txt,vtt,wasm,wav,webm,webmanifest,webp,woff,woff2,xls,xlsx,xml,xsl,zip\",\"s_files\":[\"administrator\\/components\\/com_akeeba\\/restore.php\",\"administrator\\/components\\/com_akeebabackup\\/restore.php\"],\"s_dirs_php\":[\"plugins\\/system\\/bfnetwork\"],\"s_dirs_static\":[],\"allow_paths\":[],\"s_dotfiles\":1,\"s_wellknown\":1,\"s_sensitive\":1,\"s_manifests\":0,\"s_sysdirs\":1,\"s_sysdirs_list\":[\"administrator\\/cache\",\"administrator\\/logs\",\"cache\",\"cli\",\"log\",\"logs\",\"tmp\"],\"p_compress\":1,\"p_precomp\":0,\"p_expires\":1,\"p_etag\":0,\"custom_top\":\"\",\"custom_bottom\":\"\",\"file_sha1\":\"dcb97f95087f2bdb336d0ffdcc300371ca6c4c51\",\"last_written\":\"2026-07-15 17:20:03\",\"last_test\":{\"checks\":[{\"label\":\"Home page reachable\",\"url\":\"https:\\/\\/www.efitec.nl\\/\",\"status\":200,\"ok\":true,\"note\":\"\"},{\"label\":\"Backend reachable (401 = password protection active)\",\"url\":\"https:\\/\\/www.efitec.nl\\/administrator\\/index.php\",\"status\":401,\"ok\":true,\"note\":\"\"},{\"label\":\"PHP shield active (test call is rejected with 403)\",\"url\":\"https:\\/\\/www.efitec.nl\\/htpx-canary-fbfbe897.php\\/htp\",\"status\":403,\"ok\":true,\"note\":\"\"},{\"label\":\"configuration.php blocked\",\"url\":\"https:\\/\\/www.efitec.nl\\/configuration.php\",\"status\":403,\"ok\":true,\"note\":\"\"}],\"regression\":false,\"reason\":\"\",\"time\":\"2026-07-15 15:20:03\"},\"guard_dir\":\"\",\"guard_recover\":\"263c210ee005a46813c42d75dd82d7144cb9b918b4356d8c60a8f9225963fe48\",\"welcome_sent\":1,\"welcome_green_since\":0,\"jed_review_ack\":\"\",\"jed_mail_last\":0,\"htaccess_cap\":[]},\"htp_defs\":{\"schema\":1,\"version\":\"2026-07-31.fa71fe\",\"signatures\":[{\"id\":\"jce-profiles-import\",\"label\":\"JCE Profil-Import (CVE-2026-48907)\",\"label_en\":\"JCE profile import (CVE-2026-48907)\",\"desc\":\"Unauthentifizierter Profil-Import im JCE-Editor - Beginn der aktuellen RCE-Kette (schaltet PHP-Uploads frei). Kein legitimer Frontend-Aufruf.\",\"desc_en\":\"Unauthenticated profile import in the JCE editor - start of the current RCE chain (enables PHP uploads). No legitimate frontend call.\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*task=profiles\\\\.import)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"jce-rpc-upload\",\"label\":\"JCE Webshell-Upload via plugin.rpc (CVE-2026-48907)\",\"label_en\":\"JCE webshell upload via plugin.rpc (CVE-2026-48907)\",\"desc\":\"Datei-Upload \\u00fcber den JCE-Dateibrowser (plugin.rpc, method=upload). Greift nur im Frontend; eingeloggte Autoren (legitimer Editor-Upload) bleiben unber\\u00fchrt.\",\"desc_en\":\"File upload via the JCE file browser (plugin.rpc, method=upload). Applies only on the frontend; logged-in authors (legitimate editor upload) are unaffected.\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*task=plugin\\\\.rpc)(?=.*method=upload)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":null},{\"id\":\"jce-imgmanager\",\"label\":\"JCE Image Manager (Alt-Exploit)\",\"label_en\":\"JCE Image Manager (legacy exploit)\",\"desc\":\"Klassischer unauthentifizierter Datei-Upload \\u00fcber den JCE-Bildmanager (sehr alte JCE-Versionen).\",\"desc_en\":\"Classic unauthenticated file upload via the JCE image manager (very old JCE versions).\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*plugin=imgmanager)(?=.*method=form)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":null},{\"id\":\"novarain-nrframework\",\"label\":\"Novarain \\/ Tassos Framework (com_ajax include)\",\"label_en\":\"Novarain \\/ Tassos Framework (com_ajax include)\",\"desc\":\"CVE-2026-21627: unauthentifizierte PHP-Datei-Einbindung \\u00fcber plg_system_nrframework via com_ajax (task=include).\",\"desc_en\":\"CVE-2026-21627: unauthenticated PHP file inclusion via plg_system_nrframework through com_ajax (task=include).\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*nrframework)(?=.*task=include)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"astroid-ajax\",\"label\":\"Astroid Framework (AJAX-Endpunkt)\",\"label_en\":\"Astroid Framework (AJAX endpoint)\",\"desc\":\"CVE-2026-21628: ungepr\\u00fcfter Astroid-AJAX-Endpunkt (Upload\\/Installation). Coarse-Match auf com_ajax + astroid.\",\"desc_en\":\"CVE-2026-21628: unchecked Astroid AJAX endpoint (upload\\/installation). Coarse match on com_ajax + astroid.\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*(plugin|template|view)=astroid)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"helix3-ajax\",\"label\":\"Helix3 (JoomShaper): unauth. com_ajax-Handler (Datei schreiben\\/l\\u00f6schen)\",\"label_en\":\"Helix3 (JoomShaper): unauth com_ajax handler (file write\\/delete)\",\"desc\":\"Helix3 < 3.1.1: der Ajax-Handler onAjaxHelix3 pr\\u00fcfte weder Login noch Rechte. Trifft gezielt die gef\\u00e4hrlichen Unauth-Aktionen im POST-Body: save (Layout-JSON ins aktive Template schreiben), remove (Datei l\\u00f6schen via Path-Traversal), import (Template-Style-Settings \\u00fcberschreiben) sowie upload_image\\/remove_image\\/updateFonts. Legitime Gast-Aktionen (voting, load) und eingeloggte Template-Nutzung \",\"desc_en\":\"Helix3 < 3.1.1: the onAjaxHelix3 ajax handler checked neither login nor permission. Targets the dangerous unauth POST-body actions: save (write layout JSON into the active template), remove (delete a file via path traversal), import (overwrite template style settings) plus upload_image\\/remove_image\\/updateFonts. Legitimate guest actions (voting, load) and logged-in template use are unaffected. Fix:\",\"default\":1,\"qs\":\"data(?:\\\\[|%5b)action(?:\\\\]|%5d)=(?:save|remove|import|updatefonts)|action=(?:upload_image|remove_image)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"helix3-comajax\",\"label\":\"Helix3 (JoomShaper): unauth. com_ajax-Dispatcher (Datei-Write\\/Delete, Style-Injektion)\",\"label_en\":\"Helix3 (JoomShaper): unauth com_ajax dispatcher (file write\\/delete, style injection)\",\"desc\":\"Helix3 < 3.1.1: der Front-Dispatcher (option=com_ajax mit plugin=helix3) rief onAjaxHelix3 VOR jeder Token-\\/Rechtepr\\u00fcfung auf - unauthentifiziert save\\/import\\/remove\\/resetLayout\\/updateFonts\\/fontVariants (Datei-Schreiben, Path-Traversal-L\\u00f6schen, Template-Style-Injektion, Stored XSS). Blockt jeden GAST-Aufruf dieses Dispatchers im Frontend (Defense-in-Depth, f\\u00e4ngt auch laufende Scans) - erg\\u00e4nzt d\",\"desc_en\":\"Helix3 < 3.1.1: the front-end dispatcher (option=com_ajax with plugin=helix3) invoked onAjaxHelix3 BEFORE any token\\/permission check - unauthenticated save\\/import\\/remove\\/resetLayout\\/updateFonts\\/fontVariants (file write, path-traversal delete, template style injection, stored XSS). Blocks every GUEST call of this dispatcher on the front end (defense in depth, also catches ongoing scans) - complemen\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*plugin=helix3\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"helixultimate-comajax\",\"label\":\"Helix Ultimate (JoomShaper): unauth. com_ajax-Dispatcher (Men\\u00fc-Write\\/Datei\\/Export)\",\"label_en\":\"Helix Ultimate (JoomShaper): unauth com_ajax dispatcher (menu write\\/file\\/export)\",\"desc\":\"Helix Ultimate < 2.2.7: der com_ajax-Handler onAjaxHelixultimate (option=com_ajax mit plugin=helixultimate, Action im task-Param) lief VOR jeder Login-\\/Rechtepr\\u00fcfung - ein anonymer Angreifer konnte in die Men\\u00fc-Einstellungen schreiben (Stored XSS bis in die Admin-Sitzung), Dateien per Path-Traversal beliebig l\\u00f6schen, einen Open Redirect ausl\\u00f6sen und das Template ungesch\\u00fctzt exportieren. Blockt\",\"desc_en\":\"Helix Ultimate < 2.2.7: the com_ajax handler onAjaxHelixultimate (option=com_ajax with plugin=helixultimate, action in the task param) ran BEFORE any login\\/permission check - an anonymous attacker could write into the menu settings (stored XSS reaching the admin session), delete files anywhere via path traversal, trigger an open redirect and export the template unprotected. Blocks every GUEST call\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*plugin=helixultimate\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"comajax-include\",\"label\":\"com_ajax: Datei-Einbindung (generisch)\",\"label_en\":\"com_ajax: file inclusion (generic)\",\"desc\":\"F\\u00e4ngt unbekannte LFI-L\\u00fccken derselben Klasse ab: com_ajax mit task=include\\/require. Frontend.\",\"desc_en\":\"Catches unknown LFI holes of the same class: com_ajax with task=include\\/require. Frontend.\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*task=(include|require)(_once)?)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"sppagebuilder-uploadicon\",\"label\":\"SP Page Builder: unauthentifizierter Icon-Upload (RCE)\",\"label_en\":\"SP Page Builder: unauthenticated icon upload (RCE)\",\"desc\":\"Zero-Day in SP Page Builder bis 6.6.1: der asset-Controller (task=asset.uploadCustomIcon) hatte keinerlei Zugriffs-\\/Login-Pr\\u00fcfung - unauthentifizierter Datei-Upload nach \\/media\\/com_sppagebuilder\\/assets\\/iconfont\\/ - RCE. Nur Mini-WAF (G\\u00e4ste), da eingeloggte Builder den Endpunkt legitim nutzen.\",\"desc_en\":\"Zero-day in SP Page Builder up to 6.6.1: the asset controller (task=asset.uploadCustomIcon) had no access\\/login check - unauthenticated file upload to \\/media\\/com_sppagebuilder\\/assets\\/iconfont\\/ - RCE. Mini-WAF only (guests), since logged-in builders use the endpoint legitimately.\",\"default\":1,\"qs\":\"(?=.*option=com_sppagebuilder)(?=.*task=asset\\\\.uploadCustomIcon)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":null},{\"id\":\"dpcalendar-createdby-sqli\",\"label\":\"DPCalendar: unauth. SQL-Injection (Autor-Filter)\",\"label_en\":\"DPCalendar: unauth SQL injection (author filter)\",\"desc\":\"DPCalendar Blind-SQLi (Joomla 4.4-6 < 10.11.2, J3 < 8.19.4): der Frontend-Autor-Filter filter_created_by (option=com_dpcalendar, view=events) floss in skalarer Form ungecastet in a.created_by IN (...) - anonymes Auslesen beliebiger DB-Tabellen (nur lesend). Blockt Gast-Anfragen, deren filter_created_by kein reiner Integer ist (legitim = Autor-IDs\\/Ziffern) -> FP-frei. Fix 10.11.2 \\/ 8.19.4.\",\"desc_en\":\"DPCalendar blind SQLi (Joomla 4.4-6 < 10.11.2, J3 < 8.19.4): the front-end author filter filter_created_by (option=com_dpcalendar, view=events) flowed uncast into a.created_by IN (...) in its scalar form - anonymous read of arbitrary DB tables (read-only). Blocks guest requests whose filter_created_by is not a pure integer (legit = author IDs\\/digits) -> FP-free. Fix 10.11.2 \\/ 8.19.4.\",\"default\":1,\"qs\":\"(?=.*option=com_dpcalendar)(?=.*filter_created_by=[0-9,]*[^0-9,&])\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_dpcalendar\"},{\"id\":\"acym-entityselect-sqli\",\"label\":\"AcyMailing: unauth. SQL-Injection (Entity-Select Spaltenliste)\",\"label_en\":\"AcyMailing: unauth SQL injection (entity-select column list)\",\"desc\":\"CVE-2026-56292 (AcyMailing 6.0.0-10.11.0): der Frontend-Endpunkt EntitySelectController::loadEntityFront (option=com_acym, task=loadEntityFront) nahm die Request-Parameter columns\\/join_table ungeprueft in die SELECT-Spaltenliste von UserClass::getMatchingElements auf - ein anonymer Besucher konnte per Subquery beliebige DB-Tabellen (inkl. Passwort-Hashes) auslesen. Blockt GAST-Aufrufe dieses Tasks\",\"desc_en\":\"CVE-2026-56292 (AcyMailing 6.0.0-10.11.0): the front-end endpoint EntitySelectController::loadEntityFront (option=com_acym, task=loadEntityFront) placed the request parameters columns\\/join_table unchecked into the SELECT column list of UserClass::getMatchingElements - an anonymous visitor could read arbitrary DB tables (incl. password hashes) via a subquery. Blocks GUEST calls of this task whose c\",\"default\":1,\"qs\":\"(?=.*option=com_acym)(?=.*task=loadEntityFront)(?=.*(?:columns|join_table|join)=[^&]*(?:\\\\(|%28|%2528|\\\\s|%20|\\\\+))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_acym\"},{\"id\":\"quix-article-sqli\",\"label\":\"Quix Page Builder: unauth. SQL-Injection (Einzel-Artikel-AJAX)\",\"label_en\":\"Quix Page Builder: unauth SQL injection (single-article AJAX)\",\"desc\":\"Quix (ThemeXpert, Free UND Pro) bis 6.2.0, inkl. der 5.x-Reihe: der oeffentliche AJAX-Endpunkt (option=com_quix, task=ajax, element=joomla-article) ruft QuixJoomlaArticleElement::getAjax() ohne Login-\\/Token-\\/Lizenz-Pruefung; die Artikel-ID kommt base64-kodiert im data-Parameter und wird in articleExist() UNGECASTET in die DB-Query konkateniert -> unauthentifizierte, fehler-basierte SQL-Injection (\",\"desc_en\":\"Quix (ThemeXpert, Free AND Pro) up to 6.2.0, incl. the 5.x line: the public AJAX endpoint (option=com_quix, task=ajax, element=joomla-article) calls QuixJoomlaArticleElement::getAjax() with no login\\/token\\/license check; the article id arrives base64-encoded in the data parameter and is concatenated UNCAST into the DB query in articleExist() -> unauthenticated error-based SQL injection (CVSS 8.7). \",\"default\":1,\"qs\":\"(?=.*option=com_quix)(?=.*task=ajax\\\\b)(?=.*element=joomla-article\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_quix\"},{\"id\":\"joomcck-tags-sqli\",\"label\":\"JoomCCK: unauth. SQL-Injection (Tag-Verwaltung)\",\"label_en\":\"JoomCCK: unauth SQL injection (tag management)\",\"desc\":\"CVE-2026-49048 (JoomCCK 6.x vor 6.4.1): der Front-End-Task tags.save\\/tags.delete (option=com_joomcck) lief OHNE Token-\\/Login-\\/Rechte-Pruefung und schob den Request-Parameter tag (getString) roh - mit Double-Quote-Ausbruch - in ZWEI aufeinanderfolgende SQL-Statements (Existenz-SELECT + UPDATE). Ein anonymer Besucher konnte die Datenbank auslesen und veraendern (stacked\\/error-based SQLi). Blockt jed\",\"desc_en\":\"CVE-2026-49048 (JoomCCK 6.x before 6.4.1): the front-end task tags.save\\/tags.delete (option=com_joomcck) ran with NO token\\/login\\/permission check and concatenated the request parameter tag (getString) raw - with a double-quote breakout - into TWO consecutive SQL statements (existence SELECT + UPDATE). An anonymous visitor could read and modify the database (stacked\\/error-based SQLi). Blocks every \",\"default\":1,\"qs\":\"(?=.*option=com_joomcck)(?=.*task=tags\\\\.(?:save|delete))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_joomcck\"},{\"id\":\"gridbox-store-register\",\"label\":\"Balbooa Gridbox: unauth. Konto-Erstellung (store.register)\",\"label_en\":\"Balbooa Gridbox: unauth account creation (store.register)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, gemeldet 2026-07-28, Fix in 2.20.2 (29.07.2026). Der Front-End-Task store.register lief OHNE Login\\/Token und legte ein Joomla-Konto mit FREI WAEHLBARER Usergruppe plus sofort gueltiger Session an (unauth Privilege Escalation). Blockt jeden Gast-Aufruf dieses Tasks. Kosten: falls die Site die Gridbox-eigene Frontend-Registrierung nu\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to and incl. 2.20.1 - actively exploited, reported 2026-07-28, fixed in 2.20.2 (29 Jul 2026). The front-end task store.register ran WITHOUT login\\/token and created a Joomla account with an ARBITRARY usergroup plus an immediately valid session (unauth privilege escalation). Blocks every guest call of this task. Cost: if the site uses Gridbox front-end registration (\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=store(\\\\.|%2e)register)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":\"com_gridbox\"},{\"id\":\"gridbox-uploader-showimage-read\",\"label\":\"Balbooa Gridbox: unauth. Datei-Lesen (uploader.showImage)\",\"label_en\":\"Balbooa Gridbox: unauth arbitrary file read (uploader.showImage)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, Fix in 2.20.2 (29.07.2026). Der Front-End-Task uploader.showImage laed ohne Login den Query-Parameter image= und gibt bei Nicht-Bildern die Datei roh aus (fopen+fpassthru) -> unauth Arbitrary File Read, u. a. configuration.php. Trifft JEDE Gridbox-Installation. SURGICAL: greift NUR, wenn image= ein Angriffsmuster enthaelt (Pfad-Kle\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to and incl. 2.20.1 - actively exploited, fixed in 2.20.2 (29 Jul 2026). The front-end task uploader.showImage reads the query parameter image= without login and, for non-images, dumps the file raw (fopen+fpassthru) -> unauth arbitrary file read incl. configuration.php. Hits EVERY Gridbox install. SURGICAL: fires ONLY when image= contains an attack pattern (travers\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=uploader(\\\\.|%2e)showImage)(?=.*image=(?:%2f|\\/|[a-z]:|[a-z]%3a|[^&]*(?:\\\\.\\\\.|%2e%2e|\\\\.php|%2ephp|%00|php:|php%3a|:%2f%2f|:\\/\\/)))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":\"com_gridbox\"},{\"id\":\"gridbox-uploader-savephoto\",\"label\":\"Balbooa Gridbox: unauth. Datei-Schreiben (uploader.savePhotoEditorImage)\",\"label_en\":\"Balbooa Gridbox: unauth arbitrary file write (uploader.savePhotoEditorImage)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, Fix in 2.20.2 (29.07.2026). Der Front-End-Task uploader.savePhotoEditorImage schreibt eine beliebige Datei (inkl. .php) in den Webroot; der Zieldateiname liegt im POST-Body (php:\\/\\/input) und ist fuer die .htaccess unsichtbar, und eingeloggte Redakteure nutzen den Endpunkt legitim. Daher waf_only + scope=guest: NUR im Echtzeit-Plugi\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to and incl. 2.20.1 - actively exploited, fixed in 2.20.2 (29 Jul 2026). The front-end task uploader.savePhotoEditorImage writes an arbitrary file (incl. .php) into the webroot; the target filename is in the POST body (php:\\/\\/input), invisible to .htaccess, and logged-in editors use the endpoint legitimately. Hence waf_only + scope=guest: enforced ONLY in the real-t\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=uploader(\\\\.|%2e)savePhotoEditorImage)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_gridbox\"},{\"id\":\"baforms-signature-rce\",\"label\":\"Balbooa Forms: unauth. RCE (Signature-Feld, CVE-2026-65880)\",\"label_en\":\"Balbooa Forms: unauth RCE (signature field, CVE-2026-65880)\",\"desc\":\"Balbooa Forms (com_baforms) bis inkl. 2.4.2.1 - CVE-2026-65880 (CVSS 10.0), aktiv ausgenutzt, Fix erst 2.4.3. Beim Absenden eines Formulars mit SIGNATURE-Feld (task=form.sendMessage) verwendet FormModel::saveSignature den vom Angreifer im Feld-JSON gelieferten Funktionsnamen dynamisch als aufgerufene Funktion mit angeh\\u00e4ngtem Wert - unauthentifizierte Remote Code Execution. Der legitime Wert ist i\",\"desc_en\":\"Balbooa Forms (com_baforms) up to and incl. 2.4.2.1 - CVE-2026-65880 (CVSS 10.0), actively exploited, fixed only in 2.4.3. Submitting a form with a SIGNATURE field (task=form.sendMessage) makes FormModel::saveSignature use the attacker-supplied function name from the field JSON dynamically as the called function with an appended value - unauthenticated remote code execution. The legitimate value i\",\"default\":1,\"qs\":\"(?=.*\\\\bmethod[^a-z0-9]{1,6}(?:system|exec|shell_exec|passthru|assert|popen|proc_open|pcntl_exec|file_get_contents|readfile|show_source|highlight_file|fopen|scandir|phpinfo|eval|create_function|call_user_func)\\\\b)(?=.*\\\\bimage\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":1,\"trigger\":\"com_baforms\"},{\"id\":\"traversal-encoded\",\"label\":\"Pfad-Klettern (kodierte Varianten)\",\"label_en\":\"Path traversal (encoded variants)\",\"desc\":\"Erg\\u00e4nzt den Standard-Filter um Umgehungstricks: ....\\/\\/ , doppelte Kodierung (%252e), %c0%ae, %2e%2e%5c.\",\"desc_en\":\"Extends the standard filter with bypass tricks: ....\\/\\/ , double encoding (%252e), %c0%ae, %2e%2e%5c.\",\"default\":1,\"qs\":\"(\\\\.{3,}\\/|%252e|%c0%a[ef]|%2e%2e%5c|\\\\.\\\\.%5c)\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"php-wrapper-uri\",\"label\":\"PHP-Stream-Wrapper im Pfad\",\"label_en\":\"PHP stream wrapper in the path\",\"desc\":\"Blockiert php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ , expect:\\/\\/ u. a. direkt im angefragten Pfad.\",\"desc_en\":\"Blocks php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ , expect:\\/\\/ etc. directly in the requested path.\",\"default\":1,\"qs\":null,\"uri\":\"(?:php|phar|data|expect|glob|zlib|zip):\\/\",\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"api-config-leak\",\"label\":\"Joomla-API Konfigurations-Leak\",\"label_en\":\"Joomla API configuration leak\",\"desc\":\"CVE-2023-23752: sch\\u00fctzt den Endpunkt \\/api\\/...\\/v1\\/config\\/application auch ohne komplette API-Sperre.\",\"desc_en\":\"CVE-2023-23752: protects the \\/api\\/...\\/v1\\/config\\/application endpoint even without a complete API block.\",\"default\":1,\"qs\":null,\"uri\":\"^api\\/index\\\\.php\\/v[0-9]+\\/config\",\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"php-object-injection\",\"label\":\"PHP Object Injection (serialisierte Payload)\",\"label_en\":\"PHP object injection (serialised payload)\",\"desc\":\"Serialisiertes PHP-Objekt in einem Parameter (O:\\/C:<L\\u00e4nge>:) - typischer Einstieg f\\u00fcr Object-Injection\\/POP-Ketten. Kommt in normalen Anfragen nicht vor.\",\"desc_en\":\"Serialised PHP object in a parameter (O:\\/C:<length>:) - typical entry point for object injection\\/POP chains. Does not occur in normal requests.\",\"default\":1,\"qs\":\"(?<![a-z0-9])[oc]:[0-9]{1,4}:\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"stream-wrapper-param\",\"label\":\"PHP-Stream-Wrapper in Parameter\",\"label_en\":\"PHP stream wrapper in a parameter\",\"desc\":\"php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ u. a. als Parameterwert - LFI\\/RCE-Vektor. Erg\\u00e4nzt die Pfad-Variante (php-wrapper-uri).\",\"desc_en\":\"php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ etc. as a parameter value - LFI\\/RCE vector. Complements the path variant (php-wrapper-uri).\",\"default\":1,\"qs\":\"(php|phar|data|expect|glob|zlib|zip):\\/{2}\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"param-traversal\",\"label\":\"Pfad-Klettern im Parameter\",\"label_en\":\"Path traversal in a parameter\",\"desc\":\"Mehrfaches ..\\/ als Parameterwert - generisches Directory-Traversal\\/LFI in beliebigen Komponenten.\",\"desc_en\":\"Repeated ..\\/ as a parameter value - generic directory traversal\\/LFI in any component.\",\"default\":1,\"qs\":\"=(\\\\.\\\\.\\/){2,}\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null}],\"vuln_extensions\":[{\"element\":\"aimycaptchalessformguard\",\"type\":\"plugin\",\"folder\":\"captcha\",\"name\":\"Aimy Captcha-Less Form Guard\",\"below\":\"20.1\",\"above\":\"17.0\",\"severity\":\"high\",\"note\":\"Sicherheitsl\\u00fccke in 18.0 bis 20.0, vom Hersteller in 20.1 behoben (freie und PRO-Edition betroffen). Kein Workaround - auf Aimy Captcha-Less Form Guard 20.1 oder neuer aktualisieren.\",\"note_en\":\"Security issue in 18.0 to 20.0, fixed by the vendor in 20.1 (free and PRO edition affected). No workaround - update to Aimy Captcha-Less Form Guard 20.1 or newer.\",\"advisory\":\"https:\\/\\/www.aimy-extensions.com\\/joomla\\/captcha-less-form-guard.html\",\"advisory_en\":\"https:\\/\\/www.aimy-extensions.com\\/joomla\\/captcha-less-form-guard.html\"},{\"element\":\"com_easystore\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EasyStore (JoomShaper)\",\"below\":\"2.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere unauthentifizierte SQL-Injections (CVE-2026-65759 ff.). Auf EasyStore 2.0.2 oder neuer aktualisieren.\",\"note_en\":\"Multiple unauthenticated SQL injections (CVE-2026-65759 ff.). Update to EasyStore 2.0.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65759\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65759\"},{\"element\":\"com_splms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP LMS (JoomShaper)\",\"below\":\"4.1.4\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-48909: unauth. Code-Ausf\\u00fchrung durch unsichere Cookie-Deserialisierung. Auf SP LMS 4.1.4 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48909: unauthenticated code execution via insecure cookie deserialization. Update to SP LMS 4.1.4 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-48909\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-48909\"},{\"element\":\"com_osmembership\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Membership Pro (JoomDonation)\",\"below\":\"4.6.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-62415: kritische L\\u00fccke durch unsichere Standardkonfiguration. Auf Membership Pro 4.6.2 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-62415: critical flaw caused by an insecure default configuration. Update to Membership Pro 4.6.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-62415\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-62415\"},{\"element\":\"com_convertforms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Convert Forms (Tassos)\",\"below\":\"5.2.3\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische L\\u00fccken bis 5.2.2 (Datei-L\\u00f6schung, Datenleck; CVE-2024-40744). Auf Convert Forms 5.2.3 oder neuer aktualisieren.\",\"note_en\":\"Multiple critical flaws up to 5.2.2 (arbitrary file deletion, data exposure; CVE-2024-40744). Update to Convert Forms 5.2.3 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2024-40744\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2024-40744\"},{\"element\":\"sourcerer\",\"type\":\"plugin\",\"folder\":\"editors-xtd\",\"name\":\"Sourcerer (Regular Labs)\",\"below\":\"12.2.9\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2025-22204: Code-Injection durch mangelnde Rechtepr\\u00fcfung. Auf Sourcerer 12.2.9 oder neuer aktualisieren.\",\"note_en\":\"CVE-2025-22204: code injection due to missing permission checks. Update to Sourcerer 12.2.9 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-22204\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-22204\"},{\"element\":\"com_easydiscuss\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EasyDiscuss (StackIdeas)\",\"below\":\"5.0.16\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-21625: ACL-Umgehung im JSON-Output (Zugriff auf gesch\\u00fctzte Forendaten). Auf EasyDiscuss 5.0.16 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21625: access-control bypass in the JSON output exposing protected forum data. Update to EasyDiscuss 5.0.16 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-21625\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-21625\"},{\"element\":\"com_komento\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Komento (StackIdeas)\",\"below\":\"4.0.8\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2025-54294: SQL-Injection, ausnutzbar durch unprivilegierte Nutzer. Auf Komento 4.0.8 oder neuer aktualisieren.\",\"note_en\":\"CVE-2025-54294: SQL injection exploitable by unprivileged users. Update to Komento 4.0.8 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-54294\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-54294\"},{\"element\":\"nrframework\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Novarain \\/ Tassos Framework\",\"below\":\"6.0.38\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-21627: unauthentifizierte PHP-Einbindung via com_ajax. Auf 6.0.38 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21627: unauthenticated PHP inclusion via com_ajax. Update to 6.0.38 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/joomla-tassos-framework-novarain-framework-sicherheitsluecke\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/joomla-tassos-framework-novarain-framework-sicherheitsluecke\"},{\"element\":\"astroid\",\"type\":\"library\",\"folder\":\"\",\"name\":\"Astroid Framework\",\"below\":\"3.3.11\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-21628: unauthentifizierter Datei-Upload via AJAX-Endpunkt (Dropper in \\/images\\/). Auf 3.3.13 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21628: unauthenticated file upload via AJAX endpoint (dropper in \\/images\\/). Update to 3.3.13 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/joomla-astroid-framework-sicherheitsluecke-vulnerability\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/joomla-astroid-framework-sicherheitsluecke-vulnerability\"},{\"element\":\"helix3\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Helix3 (JoomShaper)\",\"below\":\"3.1.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Unauthentifizierter com_ajax-Handler (onAjaxHelix3) ohne Login-\\/Rechtepr\\u00fcfung: Angreifer k\\u00f6nnen Dateien ins aktive Template schreiben oder per Path-Traversal l\\u00f6schen (save\\/remove\\/import). Auf Helix3 3.1.1 oder neuer aktualisieren.\",\"note_en\":\"Unauthenticated com_ajax handler (onAjaxHelix3) with no login or permission check: attackers can write files into the active template or delete files via path traversal (save\\/remove\\/import). Update to Helix3 3.1.1 or newer.\",\"advisory\":\"https:\\/\\/htprotect.org\\/helix3\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/helix3\"},{\"element\":\"helixultimate\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Helix Ultimate (JoomShaper)\",\"below\":\"2.2.7\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Kritische unauth. L\\u00fccke in ALLEN Versionen < 2.2.7: der com_ajax-Handler onAjaxHelixultimate lief VOR jeder Rechtepr\\u00fcfung - anonym in die Men\\u00fcs schreiben (Stored XSS in den Admin), Path-Traversal-L\\u00f6schen, Open Redirect, Template-Export. Auf 2.2.7 updaten (Plugin UND Template). HTProtects Mini-WAF blockt den Aufruf bereits. NICHT mit Helix3 verwechseln.\",\"note_en\":\"Critical unauth flaw in ALL versions below 2.2.7: the com_ajax handler onAjaxHelixultimate ran before any permission check - anonymous menu writes (stored XSS reaching the admin), path-traversal delete, open redirect, template export. Update to 2.2.7 (plugin AND template). HTProtect mini-WAF already blocks the call. Not to be confused with Helix3.\",\"advisory\":\"https:\\/\\/htprotect.org\\/helix-ultimate\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/helix-ultimate\"},{\"element\":\"com_baforms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Balbooa Forms\",\"below\":\"2.4.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Aktiver Zero-Day (RCE), ALLE Versionen bis 2.4.0: der Upload-Endpoint form.uploadAttachmentFile pr\\u00fcft weder Login\\/Token noch Dateityp - ein anonymer Angreifer kann eine PHP-Datei hochladen und ausf\\u00fchren. NOCH KEIN Patch. Sofortma\\u00dfnahme: Upload-Formulare depublizieren. HTProtects Gast-Upload-Schutz blockt den ausf\\u00fchrbaren Upload bereits.\",\"note_en\":\"Active zero-day (RCE), ALL versions up to 2.4.0: the upload endpoint form.uploadAttachmentFile checks neither login\\/token nor file type - an anonymous attacker can upload and run a PHP file. NO patch yet. Interim: unpublish forms with upload fields. The HTProtect guest-upload filter already blocks the executable upload.\",\"advisory\":\"https:\\/\\/htprotect.org\\/balbooa-forms\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/balbooa-forms\"},{\"element\":\"com_jce\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JCE Editor\",\"below\":\"2.9.99.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-48907: unauthentifizierter Webshell-Upload (profiles.import + plugin.rpc). Dringend auf JCE 2.9.99.6 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48907: unauthenticated webshell upload (profiles.import + plugin.rpc). Urgently update to JCE 2.9.99.6 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/jce-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/jce-sicherheitsluecke-joomla\"},{\"element\":\"com_rsfiles\",\"type\":\"component\",\"folder\":\"\",\"name\":\"RSFiles!\",\"below\":\"1.17.12\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Aktiver unauthentifizierter Datei-Upload -> RCE, ALLE Versionen bis 1.17.11: der Frontend-Upload (task=rsfiles.upload) pr\\u00fcft weder Login\\/Token noch Dateiendung - ein anonymer Angreifer l\\u00e4dt eine .php nach \\/downloads bzw. \\/briefcase und f\\u00fchrt sie aus. Dringend auf 1.17.12 aktualisieren. HTProtects Gast-Upload-Schutz blockt den ausf\\u00fchrbaren Upload bereits.\",\"note_en\":\"Active unauthenticated file upload -> RCE, ALL versions up to 1.17.11: the front-end upload (task=rsfiles.upload) checks neither login\\/token nor file extension - an anonymous attacker uploads a .php into \\/downloads or \\/briefcase and executes it. Update to 1.17.12 urgently. The HTProtect guest-upload filter already blocks the executable upload.\",\"advisory\":\"https:\\/\\/www.rsjoomla.com\\/blog\\/view\\/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html\",\"advisory_en\":\"https:\\/\\/www.rsjoomla.com\\/blog\\/view\\/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html\"},{\"element\":\"com_edocman\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EDocman\",\"below\":\"3.9\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Unauthentifizierte SQL-Injection (alle Versionen bis 3.8): ein anonymer Besucher schleust ueber einen Filter-Parameter eines oeffentlichen Frontend-Endpunkts SQL in eine ungequotete DB-Abfrage ein und kann die Datenbank auslesen (bis hin zu Zugangsdaten). Der genaue Vektor ist bewusst nicht veroeffentlicht. Dringend auf EDocman 3.9.0 aktualisieren.\",\"note_en\":\"Unauthenticated SQL injection (all versions up to 3.8): an anonymous visitor injects SQL through a filter parameter of a public front-end endpoint into an unquoted DB query and can read the database (up to credentials). The exact vector is deliberately undisclosed. Update to EDocman 3.9.0 urgently.\",\"advisory\":\"https:\\/\\/joomdonation.com\\/forum\\/edocman\\/82813-edocman-3-9-0-security-release---important-update-recommended.html\",\"advisory_en\":\"https:\\/\\/joomdonation.com\\/forum\\/edocman\\/82813-edocman-3-9-0-security-release---important-update-recommended.html\"},{\"element\":\"com_foranalytics\",\"type\":\"component\",\"folder\":\"\",\"name\":\"4Analytics\",\"below\":\"5.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Zwei unauthentifizierte Sicherheitsluecken (CVE-2026-57833 + CVE-2026-58077) in ALLEN Versionen vor 5.0.2 - ein anonymer Angreifer braucht keinen Login. Hersteller Weeblr stuft beide als kritisch ein; technische Details sind 7 Tage embargoed. Dringend auf 4Analytics 5.0.2 aktualisieren (laeuft auf Joomla 3-6).\",\"note_en\":\"Two unauthenticated security flaws (CVE-2026-57833 + CVE-2026-58077) in ALL versions before 5.0.2 - an anonymous attacker needs no login. Vendor Weeblr rates both critical; technical details are under a 7-day embargo. Update to 4Analytics 5.0.2 urgently (runs on Joomla 3-6).\",\"advisory\":\"https:\\/\\/weeblr.com\\/blog\\/critical-vulnerabilities-2026-07-15\",\"advisory_en\":\"https:\\/\\/weeblr.com\\/blog\\/critical-vulnerabilities-2026-07-15\"},{\"element\":\"com_quix\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Quix\",\"below\":\"6.2.1\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Unauthentifizierte SQL-Injection (Free UND Pro, alle Versionen vor 6.2.1 \\u2013 auch die 5.x-Reihe): ein anonymer Besucher kann die gesamte Datenbank auslesen (CVSS 8.7). HTProtects Mini-WAF blockt den Angriff bereits aktiv. Auf Quix 6.2.1 aktualisieren (Free erh\\u00e4lt 6.2.1 ebenfalls \\u00fcber die Update-Funktion).\",\"note_en\":\"Unauthenticated SQL injection (Free AND Pro, all versions below 6.2.1 \\u2013 including the 5.x line): an anonymous visitor can read the entire database (CVSS 8.7). HTProtect\'s mini-WAF already actively blocks the attack. Update to Quix 6.2.1 (Free receives 6.2.1 too via the update function).\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/quix-sql-injection-disclosure\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/quix-sql-injection-disclosure\\/\"},{\"element\":\"com_joomcck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JoomCCK\",\"below\":\"6.4.1\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"Unauthentifizierte SQL-Injection (CVE-2026-49048, JoomCCK 6.x vor 6.4.1): der Front-End-Task \\u201eTag speichern\\/l\\u00f6schen\\\" pr\\u00fcfte weder Login noch Token und \\u00fcbernahm den Parameter \\u201etag\\\" ungefiltert in zwei SQL-Abfragen - ein anonymer Besucher konnte die Datenbank auslesen und ver\\u00e4ndern. HTProtects Mini-WAF blockt den unautorisierten Gast-Aufruf bereits aktiv. Dringend auf JoomCCK 6.4.1 aktualisi\",\"note_en\":\"Unauthenticated SQL injection (CVE-2026-49048, JoomCCK 6.x before 6.4.1): the front-end \\\"save\\/delete tag\\\" task checked neither login nor token and took the \\\"tag\\\" parameter unfiltered into two SQL queries - an anonymous visitor could read and modify the database. HTProtect\'s mini-WAF already actively blocks the unauthorized guest call. Update to JoomCCK 6.4.1 urgently.\",\"advisory\":\"https:\\/\\/github.com\\/JoomCoder-com\\/JoomCCK\\/releases#release-6.4.1\",\"advisory_en\":\"https:\\/\\/github.com\\/JoomCoder-com\\/JoomCCK\\/releases#release-6.4.1\"},{\"element\":\"com_chronoforms8\",\"type\":\"component\",\"folder\":\"\",\"name\":\"ChronoForms\",\"below\":\"8.0.53\",\"above\":\"8.0.0\",\"severity\":\"high\",\"note\":\"Unauthentifizierte gespeicherte XSS (CVE-2026-58148, ChronoForms 8.x vor 8.0.53): ein anonymer Besucher schleust \\u00fcber ein Formular-Feld JavaScript ein, das ungefiltert gespeichert und sp\\u00e4ter - z. B. beim Ansehen der Einsendungen im Backend - ausgef\\u00fchrt wird, bis hin zur \\u00dcbernahme der Admin-Sitzung (CVSS 8.7). Auf ChronoForms 8.0.53 aktualisieren.\",\"note_en\":\"Unauthenticated stored XSS (CVE-2026-58148, ChronoForms 8.x before 8.0.53): an anonymous visitor injects JavaScript via a form field that is stored unfiltered and later executed - e.g. when viewing the submissions in the backend - up to takeover of the admin session (CVSS 8.7). Update to ChronoForms 8.0.53.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-58148\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-58148\"},{\"element\":\"com_jdownloads\",\"type\":\"component\",\"folder\":\"\",\"name\":\"jDownloads\",\"below\":\"4.1.6\",\"above\":\"4.1.0\",\"severity\":\"high\",\"note\":\"Unauthentifizierte Datei-Upload-L\\u00fccke (jDownloads 4.1.0-4.1.5): eine verwaiste Uploader-Datei (upload-handler.php) pr\\u00fcft weder Login noch Token und l\\u00e4sst einen anonymen Besucher beliebige Dateien - u. a. exe\\/msi\\/Archive - in einen Ordner der Site schreiben; auf manchen Servern bis zur Codeausf\\u00fchrung, sonst Malware-Hosting\\/Speicher-Flutung. HTProtects .htaccess-Schutzschild blockt den direkten \",\"note_en\":\"Unauthenticated file upload flaw (jDownloads 4.1.0-4.1.5): a leftover uploader file (upload-handler.php) checks neither login nor token and lets an anonymous visitor write arbitrary files - incl. exe\\/msi\\/archives - into a folder on the site; up to remote code execution on some servers, otherwise malware hosting \\/ disk flooding. HTProtect\'s .htaccess shield already blocks direct access to the file \",\"advisory\":\"https:\\/\\/www.jdownloads.com\\/index.php\\/news\\/jdownloads-4-1-6-secure-update-released.html\",\"advisory_en\":\"https:\\/\\/www.jdownloads.com\\/index.php\\/news\\/jdownloads-4-1-6-secure-update-released.html\"},{\"element\":\"com_dpcalendar\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DPCalendar\",\"below\":\"10.11.2\",\"above\":\"9.0.0\",\"severity\":\"high\",\"note\":\"DPCalendar (Joomla 4.4-6, 9.0.0-10.11.1): unauthentifizierte Blind-SQL-Injection - der Autor-Filter filter_created_by (Frontend view=events) floss in skalarer Form ohne Integer-Cast in die Query (a.created_by IN ...); ein anonymer Besucher kann beliebige DB-Tabellen AUSLESEN (nichts \\u00e4ndern). Dringend auf 10.11.2 aktualisieren. HTProtects Mini-WAF blockt die Injektion bereits.\",\"note_en\":\"DPCalendar (Joomla 4.4-6, 9.0.0-10.11.1): unauthenticated blind SQL injection - the author filter filter_created_by (front-end view=events) flowed uncast (scalar form) into the query (a.created_by IN ...); an anonymous visitor can READ arbitrary DB tables (no writes). Update to 10.11.2 urgently. HTProtect mini-WAF already blocks the injection.\",\"advisory\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\",\"advisory_en\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\"},{\"element\":\"com_dpcalendar\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DPCalendar\",\"below\":\"8.19.4\",\"above\":\"8.18.0\",\"severity\":\"high\",\"note\":\"DPCalendar Joomla-3-Linie (8.x), 8.18.0-8.19.3: dieselbe unauth Blind-SQL-Injection \\u00fcber den Autor-Filter filter_created_by (skalar, ohne Integer-Cast, nur lesend). In 8.19.4 (Joomla-3-Fix) behoben. Auf 8.19.4 aktualisieren. HTProtects Mini-WAF blockt die Injektion bereits.\",\"note_en\":\"DPCalendar Joomla 3 line (8.x), 8.18.0-8.19.3: same unauth blind SQL injection via the author filter filter_created_by (scalar, no integer cast, read-only). Fixed in 8.19.4 (Joomla 3 fix). Update to 8.19.4. HTProtect mini-WAF already blocks the injection.\",\"advisory\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\",\"advisory_en\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\"},{\"element\":\"com_phocadownload\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Download\",\"below\":\"6.1.3\",\"above\":\"6.0.0\",\"severity\":\"high\",\"note\":\"Authentifizierter Datei-Upload -> RCE (Versionen 6.0 bis 6.1.2): ein eingeloggter Nutzer mit Zugriff auf die Upload-Funktion kann eine ausf\\u00fchrbare Datei (z. B. .php) hochladen und ausf\\u00fchren. In 6.1.3 (Security-Release) behoben - auf 6.1.3 oder neuer aktualisieren. HTProtects PHP-Schild verhindert die Ausf\\u00fchrung einer hochgeladenen PHP-Datei in den Upload-Ordnern bereits.\",\"note_en\":\"Authenticated file upload -> RCE (versions 6.0 to 6.1.2): a logged-in user with access to the upload feature can upload and run an executable file (e.g. .php). Fixed in 6.1.3 (security release) - update to 6.1.3 or newer. The HTProtect PHP shield already prevents execution of an uploaded PHP file in the upload folders.\",\"advisory\":\"https:\\/\\/www.phoca.cz\\/news\\/1481-phoca-download-version-6-1-3-released-security-release\",\"advisory_en\":\"https:\\/\\/www.phoca.cz\\/news\\/1481-phoca-download-version-6-1-3-released-security-release\"},{\"element\":\"com_phocamaps\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Maps\",\"below\":\"6.1.0\",\"above\":\"5.0.0\",\"severity\":\"medium\",\"note\":\"CVE-2026-65763: reflektiertes XSS (5.0.0-6.0.4) durch unzureichende Eingabepr\\u00fcfung - ein Angreifer bringt einen Besucher \\u00fcber einen pr\\u00e4parierten Link dazu, eingeschleustes JavaScript auszuf\\u00fchren. Auf Phoca Maps 6.1.0 (Security-Release) oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-65763: reflected XSS (5.0.0-6.0.4) via improper input validation - an attacker lures a visitor with a crafted link to run injected JavaScript. Update to Phoca Maps 6.1.0 (security release) or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65763\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65763\"},{\"element\":\"com_phocaguestbook\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Guestbook\",\"below\":\"6.1.1\",\"above\":\"5.0.0\",\"severity\":\"medium\",\"note\":\"CVE-2026-65762: reflektiertes XSS (5.0.0-6.1.0) durch unzureichende Eingabepr\\u00fcfung - ein pr\\u00e4parierter Link f\\u00fchrt beim Besucher eingeschleustes JavaScript aus. Auf Phoca Guestbook 6.1.1 (Security-Release) oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-65762: reflected XSS (5.0.0-6.1.0) via improper input validation - a crafted link runs injected JavaScript in the visitor\'s browser. Update to Phoca Guestbook 6.1.1 (security release) or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65762\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65762\"},{\"element\":\"com_acym\",\"type\":\"component\",\"folder\":\"\",\"name\":\"AcyMailing 6+\",\"below\":\"10.11.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"AcyMailing Neuauflage (6+): CVE-2026-56292 unauthentifizierte SQL-Injection (6.0.0-10.11.0) - ein anonymer Angreifer liest beliebige DB-Tabellen inkl. Passwort-Hashes (CVSS 8.7). \\u00c4ltere L\\u00fccken: CVE-2023-28731 unauth Upload\\/RCE unter 8.3.0, CVE-2026-3614 Rechteausweitung 9.11.0-10.8.1. Dringend auf 10.11.1 aktualisieren.\",\"note_en\":\"AcyMailing new line (6+): CVE-2026-56292 unauthenticated SQL injection (6.0.0-10.11.0) - an anonymous attacker reads arbitrary DB tables incl. password hashes (CVSS 8.7). Older holes: CVE-2023-28731 unauth upload\\/RCE below 8.3.0, CVE-2026-3614 privilege escalation 9.11.0-10.8.1. Update to 10.11.1 urgently.\",\"advisory\":\"https:\\/\\/htprotect.org\\/acymailing\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/acymailing\"},{\"element\":\"com_acymailing\",\"type\":\"component\",\"folder\":\"\",\"name\":\"AcyMailing Classic\",\"below\":\"4.9.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"AcyMailing Classic (End-of-Life): \\u00e4ltere Versionen mit kritischen L\\u00fccken - unauthentifizierter Datei-Upload der 3.x-\\u00c4ra (RCE, z. B. 3.9.0) sowie Backend-SQL-Injection CVE-2015-7338 (in 4.9.5 behoben). Auf eine unterst\\u00fctzte AcyMailing-Version migrieren. (Die 5.x-Linie hat keine bekannte sehr kritische L\\u00fccke; CSV-Injection CVE-2018-9107 in 5.9.1-5.9.5 ist niedrig\\/client-seitig.)\",\"note_en\":\"AcyMailing Classic (end-of-life): older versions with critical holes - unauthenticated file upload of the 3.x era (RCE, e.g. 3.9.0) and backend SQL injection CVE-2015-7338 (fixed in 4.9.5). Migrate to a supported AcyMailing version. (The 5.x line has no known very critical hole; CSV injection CVE-2018-9107 in 5.9.1-5.9.5 is low\\/client-side.)\",\"advisory\":\"https:\\/\\/htprotect.org\\/acymailing\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/acymailing\"},{\"element\":\"com_igallery\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Ignite Gallery\",\"below\":\"5.4.1\",\"above\":\"5.0.0\",\"severity\":\"high\",\"note\":\"Ignite Gallery 5.0.0 bis 5.4.0: Stored XSS (hoch) durch fehlendes Output-Escaping beim Hochladen\\/Bearbeiten von Bildern, dazu SSRF (ungefilterte Video-URL) und eine Rechteausweitung beim Download geschuetzter\\/unveroeffentlichter Bilder. Ausnutzbar von Nutzern MIT Upload-\\/Bearbeitungsrecht (Frontend oder Backend). Auf 5.4.1 oder neuer aktualisieren.\",\"note_en\":\"Ignite Gallery 5.0.0 to 5.4.0: stored XSS (high) via missing output escaping when uploading\\/editing images, plus SSRF (unfiltered video URL) and a privilege escalation when downloading restricted\\/unpublished images. Exploitable by users WITH upload\\/edit permission (frontend or backend). Update to 5.4.1 or newer.\",\"advisory\":\"https:\\/\\/www.ignitegallery.com\\/documentation\\/changelog\",\"advisory_en\":\"https:\\/\\/www.ignitegallery.com\\/documentation\\/changelog\"},{\"element\":\"com_icagenda\",\"type\":\"component\",\"folder\":\"\",\"name\":\"iCagenda\",\"below\":\"4.0.8\",\"above\":\"4.0.0\",\"severity\":\"critical\",\"note\":\"CVE-2026-48939 (4.x-Linie 4.0.0-4.0.7): das Event-Formular (task=submit.submit) pr\\u00fcft nur das CSRF-Token, keine Zugriffsrechte - anonymer Datei-Upload. Voller RCE nur auf Joomla 6 (Core blockt .php nicht mehr); auf Joomla <=5 mildert der Core-Filter, die Zugriffsl\\u00fccke bleibt. Dringend auf 4.0.8 aktualisieren. HTProtects Dateischild verhindert die Ausf\\u00fchrung bereits.\",\"note_en\":\"CVE-2026-48939 (4.x line 4.0.0-4.0.7): the event form (task=submit.submit) checks only the CSRF token, no access rights - anonymous file upload. Full RCE only on Joomla 6 (core no longer blocks .php); on Joomla <=5 the core filter mitigates but the access flaw remains. Update to 4.0.8 urgently. The HTProtect file shield already prevents execution.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/icagenda-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/icagenda-sicherheitsluecke-joomla\"},{\"element\":\"com_icagenda\",\"type\":\"component\",\"folder\":\"\",\"name\":\"iCagenda\",\"below\":\"3.9.15\",\"above\":\"3.2.1\",\"severity\":\"critical\",\"note\":\"CVE-2026-48939, 3.x-Linie 3.2.1-3.9.14: dieselbe Zugriffsl\\u00fccke im Event-Formular (task=submit.submit, keine Rechtepr\\u00fcfung, anonymer Datei-Upload). In 3.9.15 (Security-Backport f\\u00fcr Joomla 3) behoben. Dringend auf 3.9.15 aktualisieren. HTProtects Dateischild verhindert die Ausf\\u00fchrung bereits. (Voller RCE v. a. auf Joomla 6.)\",\"note_en\":\"CVE-2026-48939, 3.x line 3.2.1-3.9.14: same access-control flaw in the event form (task=submit.submit, no permission check, anonymous file upload). Fixed in 3.9.15 (security backport for Joomla 3). Update to 3.9.15 urgently. The HTProtect file shield already prevents execution. (Full RCE mainly on Joomla 6.)\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/icagenda-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/icagenda-sicherheitsluecke-joomla\"},{\"element\":\"com_sppagebuilder\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP Page Builder\",\"below\":\"6.7.1\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"Unauthentifizierte SQL-Injection (CVE-2026-65766) bis Version 6.7.0: ein anonymer Besucher liest \\u00fcber einen ungefilterten Parameter (direction) im Dynamic-Content-Endpunkt beliebige Datenbank-Tabellen aus - bis zu Benutzerkonten, Passwort-Hashes und dem Seiten-Geheimnis (CVSS 8.7). Dazu ein offenes Mail-Relay (CVE-2026-65877): Angreifer verschicken \\u00fcber die Kontaktformular-Addons beliebige E-Mai\",\"note_en\":\"Unauthenticated SQL injection (CVE-2026-65766) up to version 6.7.0: via an unfiltered parameter (direction) in the Dynamic Content endpoint an anonymous visitor can read arbitrary database tables - down to user accounts, password hashes and the site secret (CVSS 8.7). Plus an open mail relay (CVE-2026-65877): attackers send arbitrary emails with a spoofed sender through the contact-form addons. Up\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/sp-page-builder-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/sp-page-builder-sicherheitsluecke-joomla\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.6\",\"above\":\"3.5.0\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) bis 3.5.10: ein Front-End-Upload-Endpunkt (zum Hinzuf\\u00fcgen von Bildern) pr\\u00fcfte nur das CSRF-Token, aber keine Zugriffsrechte und keinen Dateityp - ein nicht eingeloggter Angreifer konnte eine beliebige Datei (z. B. PHP-Shell) in einen frei w\\u00e4hlbaren Ordner hochladen und ausf\\u00fchren (Remote Code Execution). Dringend auf 3.6.0 aktualisieren. (HTProtects generischer Upload-Sch\",\"note_en\":\"Critical flaw (RCE) up to 3.5.10: a front-end upload endpoint (for adding images) only verified the CSRF token but no access rights and no file type - an unauthenticated attacker could upload an arbitrary file (e.g. a PHP shell) into a freely chosen folder and execute it (remote code execution). Update to 3.6.0 urgently. (The HTProtect generic upload protection already blocks the unauthenticated u\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.4.10\",\"above\":\"3.2.0\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) in der Joomla-4-Linie unter 3.4.10: unauthentifizierter Datei-Upload \\u00fcber einen Front-End-Endpunkt (nur CSRF-Token, keine Zugriffs-\\/Typpr\\u00fcfung) - beliebige Datei in frei w\\u00e4hlbaren Ordner hochladbar und ausf\\u00fchrbar. In 3.4.10 (Backport) behoben. Dringend aktualisieren. (HTProtects generischer Upload-Schutz blockt den unauthentifizierten Upload bereits; das Dateischild verh\",\"note_en\":\"Critical flaw (RCE) in the Joomla 4 line below 3.4.10: unauthenticated file upload via a front-end endpoint (CSRF token only, no access\\/type check) - arbitrary file uploadable into a freely chosen folder and executable. Fixed in 3.4.10 (backport). Update urgently. (The HTProtect generic upload protection already blocks the unauthenticated upload; the file shield additionally prevents execution.)\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.1.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) in der Joomla-3-Linie unter 3.1.1: unauthentifizierter Datei-Upload \\u00fcber einen Front-End-Endpunkt (nur CSRF-Token, keine Zugriffs-\\/Typpr\\u00fcfung) - beliebige Datei in frei w\\u00e4hlbaren Ordner hochladbar und ausf\\u00fchrbar. In 3.1.1 (Backport f\\u00fcr Joomla 3) behoben. Dringend aktualisieren. (HTProtects generischer Upload-Schutz blockt den unauthentifizierten Upload bereits; das Date\",\"note_en\":\"Critical flaw (RCE) in the Joomla 3 line below 3.1.1: unauthenticated file upload via a front-end endpoint (CSRF token only, no access\\/type check) - arbitrary file uploadable into a freely chosen folder and executable. Fixed in 3.1.1 (backport for Joomla 3). Update urgently. (The HTProtect generic upload protection already blocks the unauthenticated upload; the file shield additionally prevents ex\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_eventbooking\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Events Booking\",\"below\":\"5.8.1\",\"above\":\"5.0\",\"severity\":\"medium\",\"note\":\"Zwei Sicherheitsl\\u00fccken ohne Anmeldung in allen Versionen der 5er-Reihe vor 5.8.1: Erstens konnte jeder anonyme Besucher \\u00fcber die Datei-Upload-Funktion des Anmeldeformulars Dateien auf dem Server ablegen - ohne Konto, ohne Anmeldung und ohne Sicherheitstoken; die Funktion war ab Werk in jeder Installation aktiv. Die abgelegten Dateien lie\\u00dfen sich anschlie\\u00dfend unter einem vorhersehbaren Namen wi\",\"note_en\":\"Two unauthenticated security flaws in all versions of the 5.x line below 5.8.1: First, any anonymous visitor could place files on the server through the file upload of the registration form - no account, no login, no security token; the feature was enabled by default in every installation. The uploaded files could then be retrieved again under a predictable name. Program files were not allowed in \",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/events-booking-unauthenticated-upload-user-enumeration\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/events-booking-unauthenticated-upload-user-enumeration\\/\"},{\"element\":\"com_djclassifieds\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DJ-Classifieds\",\"below\":\"3.11.2\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Schwerwiegende L\\u00fccke in allen Versionen bis einschlie\\u00dflich 3.11.1: Die Funktion zum Hochladen von Anzeigenbildern nahm Dateien entgegen, ohne dass eine Anmeldung n\\u00f6tig war und ohne die \\u00fcblichen Sicherheitspr\\u00fcfungen. Angreifer konnten dadurch eine Schaddatei auf der Website ablegen und im ung\\u00fcnstigen Fall die Kontrolle \\u00fcber die gesamte Seite \\u00fcbernehmen. Die L\\u00fccke wurde bereits aktiv ausgen\",\"note_en\":\"Serious flaw in all versions up to and including 3.11.1: the image upload used for classified ads accepted files without requiring a login and without the usual security checks. This allowed attackers to place a malicious file on the website and, in the worst case, take control of the entire site. The flaw was already being actively exploited before a fix was available. Update to version 3.11.2 or\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/dj-classifieds-unauthenticated-file-upload\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/dj-classifieds-unauthenticated-file-upload\\/\"},{\"element\":\"com_gridbox\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Gridbox\",\"below\":\"2.20.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Balbooa hat in zwei Schritten reagiert: 2.20.1 (20.07.2026) schloss eine kritische Anmelde-L\\u00fccke (CVE-2026-61425), blieb aber unvollst\\u00e4ndig. Erst 2.20.2 (29.07.2026) behebt - laut Hersteller in allen Versionen bis einschlie\\u00dflich 2.20.1 - unbefugten Dateizugriff (Lesen und Schreiben), das rekursive L\\u00f6schen ganzer Ordner, mehrere SQL-Einschleusungen, weitere Umgehungen der Rechtepr\\u00fcfung und Inf\",\"note_en\":\"Balbooa responded in two steps: 2.20.1 (20 Jul 2026) closed a critical authentication flaw (CVE-2026-61425) but was incomplete. Only 2.20.2 (29 Jul 2026) fixes - across all versions up to and including 2.20.1, per the vendor - unauthorized file access (read and write), recursive deletion of whole directories, multiple SQL injections, further authorization-check bypasses and information disclosure.\",\"advisory\":\"https:\\/\\/www.balbooa.com\\/blog\\/gridbox\\/gridbox-2-20-2-security-release\",\"advisory_en\":\"https:\\/\\/www.balbooa.com\\/blog\\/gridbox\\/gridbox-2-20-2-security-release\"}],\"php_min\":\"8.1\",\"fetched\":\"2026-08-01 01:42:25\",\"fetched_ts\":1785615665,\"etag\":\"\\\"6a6d343c-f907\\\"\",\"modified\":\"Fri, 31 Jul 2026 23:48:12 GMT\",\"joomla_latest\":{\"3\":\"3.10.12\",\"4\":\"4.4.14\",\"5\":\"5.4.7\",\"6\":\"6.1.2\"},\"joomla_latest_ts\":1785590511,\"joomla_latest_try\":1785590511},\"htp_malware\":{\"schema\":1,\"version\":\"2026-07-29.671bb5\",\"sigs\":[{\"id\":\"backdoor-prepend-sshkey\",\"all\":[\"auto_prepend_file\",\"authorized_keys\"]},{\"id\":\"cred-stealer-ctfaudit\",\"any\":[\"x-ctf-audit\",\"jlib_audit_gid\"]},{\"id\":\"upload-shell-form\",\"all\":[\"move_uploaded_file\",\"check directory permissions\"]},{\"id\":\"sppb-iconfont-shell\",\"any\":[\"sppbwhoami\"]},{\"id\":\"remote-eval-loader\",\"all\":[\"eval(\\\"?>\\\"\"],\"any\":[\"fetchcontentfromurl\",\"file_get_contents(\\\"http\",\"file_get_contents(\'http\"]},{\"id\":\"seo-doorway-slot\",\"any\":[\"slot gacor\",\"situs slot gacor\"]},{\"id\":\"filemanager-backdoor-data\",\"all\":[\"<?php exit;?>{\",\"\\\"groupinfo\\\"\",\"\\\"sizemax\\\"\"]},{\"id\":\"encrypted-eval-openssl\",\"all\":[\"openssl_raw_data\",\"aes-256-cbc\"],\"not\":[\"openssl_decrypt\",\"openssl_encrypt\"]},{\"id\":\"0xnix-split-encrypted\",\"all\":[\"0xnix encrypted code\"]},{\"id\":\"upload-shell-devco1\",\"all\":[\"move_uploaded_file\",\"devco1\"]},{\"id\":\"upload-shell-uname-form\",\"all\":[\"move_uploaded_file\",\"php_uname\",\"multipart\\/form-data\"]},{\"id\":\"hacktool-adminer\",\"all\":[\"adminer_errors\",\"idf_unescape\"]},{\"id\":\"webshell-range-obfuscator\",\"all\":[\"\\\"r\\\".\\\"a\\\".\\\"n\\\".\\\"g\\\".\\\"e\\\"\",\"eval\"]},{\"id\":\"webshell-md5quad-gate\",\"all\":[\"md5(md5(md5(md5(\",\"eval\"]},{\"id\":\"remote-loader-stream-include\",\"any\":[\"include stream_get_meta_data\",\"require stream_get_meta_data\",\"include(stream_get_meta_data\",\"require(stream_get_meta_data\"]},{\"id\":\"webshell-dual-uploader\",\"all\":[\"remote_url\",\"name=\\\"_upl\\\"\",\"name=\\\"_remote\\\"\"]},{\"id\":\"webshell-comment-obfuscator\",\"all\":[\"-*\\/\\/\\/\",\"\\\"~\\\"\"]},{\"id\":\"eval-openssl-shell\",\"label\":\"eval(openssl_decrypt) webshell\",\"all\":[\"eval(openssl_decrypt(\"]},{\"id\":\"dropper-drivergenius-c2\",\"label\":\"Remote-fetch dropper (drivergenius C2)\",\"all\":[\"drivergenius.it.com\"]},{\"id\":\"dropper-backdate-disguise\",\"label\":\"Remote-fetch dropper (mtime-forge + disguise)\",\"all\":[\"getreferencefiletime\",\"generatefilename\"]},{\"id\":\"js-inject-fake-cleaned\",\"label\":\"JS injection w\\/ fake \\\"cleaned\\/safe\\\" comment\",\"all\":[\"artifacts of previous malicious infection\",\"dangerous code has been removed\"]},{\"id\":\"linkforge-seo-injector\",\"label\":\"LinkForge SEO backlink injector\",\"all\":[\"linkforge.cc\"]},{\"id\":\"seo-doorway-cloak\",\"label\":\"SEO cloaking doorway (Thai gambling, fake sitemap)\",\"all\":[\"output_sitemap_page\",\"is_from_google\",\"send_404_and_exit\"]},{\"id\":\"helix-ultimate-xss\",\"label\":\"Helix Ultimate mega-menu XSS campaign\",\"any\":[\"xss.report\",\"_hu_inject\",\"_huinject\",\"sessionstorage._hxd\"]},{\"id\":\"gsocket-c2\",\"label\":\"gsocket reverse-shell C2 marker\",\"any\":[\"gs_args\"]},{\"id\":\"cloak-engine-thiscitze\",\"label\":\"thiscitze SEO cloaking engine\",\"all\":[\"thiscitze\"]},{\"id\":\"cloak-doorway-jsurl-jumpurl\",\"label\":\"Thai gambling SEO cloaking\\/doorway injector\",\"all\":[\"$js_url\",\"$jump_url\"]},{\"id\":\"cn-aes-loader\",\"label\":\"AES-decrypt + gzinflate eval loader\",\"all\":[\"openssl_decrypt\",\"gzinflate\",\"eval(\\\"?>\\\"\"]},{\"id\":\"cn-loader-tag\",\"label\":\"Chinese \'PHP code security loader\' tag\",\"all\":[\"php\\u4ee3\\u7801\\u5b89\\u5168\\u52a0\\u8f7d\\u5668\"]},{\"id\":\"menu-api-filemanager\",\"label\":\"MENU_API file-manager webshell\",\"all\":[\"menu_api_password\"]},{\"id\":\"remote-eval-curl\",\"label\":\"curl remote-fetch eval loader\",\"all\":[\"eval(\\\"?>\\\"\",\"curl_exec\"]},{\"id\":\"bujang-c2\",\"label\":\"Remote-fetch loader (bujang.online C2)\",\"all\":[\"bujang.online\"]},{\"id\":\"tinyfilemanager-tool\",\"label\":\"Tiny File Manager (webshell-capable file manager)\",\"all\":[\"tinyfilemanager\"]}],\"names\":[{\"id\":\"probe-d1337\",\"m\":[\"_d1337_\"],\"label\":\"d1337 write-access probe \\/ dropper marker\"},{\"id\":\"probe-write-test\",\"m\":[\"_probe_\"],\"label\":\"generic write-access probe marker (_probe_)\"}],\"scan_ext\":[],\"ack\":[\"6608daed700e0afc330788b2a272ca8d\",\"67b5f9a00c7aabf34261c715aeeaadba\",\"9812b693256a0c306cc53368559c7a4b\",\"ec96a3bed6681af996fd37f0818cba6b\",\"abfe3b7513994ae6ac2f33129b5f6e7b\",\"fb2e76c5ebafc2b8ea82e0d35d45fa02\",\"2ec54ce00420cd41dfae5abedc9edcb7\",\"02c1a767857c55d31cae7277bc43bac2\",\"573a5e7374be2925911b552d485a28f3\",\"cdf24443c39d943f8750d4a4420e6581\",\"99af93b919c5b6bc14a82382c39010ec\",\"55e704bb88a8f9ab0d756976c527516b\",\"981b4f5e07bf9cd1249d60d659e4ef93\",\"87d978102ed075a8e58074a0d3595c30\",\"85648deb8324a11400ecaebcfd04ae16\",\"323707d28051b4cbf161420f5f1bb499\",\"19104a261abbdffe7cd1713949b286cf\",\"a72013015988ad7d978ce9841a9668dd\",\"a8af9b93d27c774601e1d8a902145bd7\",\"82c8de717e67a620ca503a1a01a7d909\",\"a8192a3cf6279862054cb3092dad82bf\",\"eae8beb708347cfe54bf87506b572f41\",\"5db6f4cdd20dfee86e05110a2276d748\",\"872e97edc1d4247d2ed86d35f468ff88\",\"da9c67c9b7be2d5a7eb9113d76119abc\",\"d0c5a881e845f93a72e1450259de0d33\",\"ea531694f501221b61a324d3754da603\",\"b8333a512d949684c91c9dd907f9cb0c\",\"2c57aea21d161fe5761ffab0abff8228\",\"93117860cd06939707a4ff1797bebb40\",\"7f58961ebcc0db81b16c2d16072fb084\",\"760423f79cedc17e78df95505e93f0c7\",\"d8b0c0f2faf44495f7954fe826720bad\",\"b9b6b8553113e745ebef3251b5d223b9\",\"3e5d03ecb5de8ab2ff1790d7b78bee24\",\"0cd3f898084fe66b062ab5162d2b370c\",\"deb26b6603b6edd8381f6c77fc53cace\",\"0855cf0d6a33b86a8506aeeb769e4343\",\"bcfa5def6057812cba39996c13c1feb3\",\"b719915e7d46c753fe4aeb7a6b8e7fea\",\"913459ac4f3b49356595a341f9b2ac03\"],\"community\":0,\"fp\":[{\"all\":[\"easycalccheckplus\"],\"only\":[\"rce\"],\"id\":\"ecc-plus-doc-rce\"},{\"all\":[\"phpoffice\\\\phpspreadsheet\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"phpspreadsheet-lib\"},{\"any\":[\"cp_errordocument\",\"status-reason\"],\"not\":[\"<!--#exec\",\"<?\"],\"only\":[\"shtml\"],\"id\":\"plesk-error-shtml\"},{\"all\":[\"gumlet\",\"data:\\/\\/application\\/octet-stream\"],\"only\":[\"wrapper\"],\"id\":\"gumlet-imageresize-datawrapper\"},{\"all\":[\"data:\\/\\/image\",\"exif_read_data\"],\"only\":[\"wrapper\"],\"id\":\"exif-data-wrapper\"},{\"all\":[\"phpoffice\\\\phpword\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"phpword-lib\"},{\"all\":[\"box\\\\spout\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"box-spout-lib\"},{\"all\":[\"sarciszewski\\\\phpfuture\"],\"only\":[\"wrapper\"],\"id\":\"php-future-lib\"},{\"all\":[\"baformsmodelform\"],\"only\":[\"feed:upload-shell-uname-form\"],\"id\":\"fp-baforms-model\"},{\"all\":[\"quixnxt\"],\"only\":[\"goto\"],\"id\":\"fp-quix-goto\"},{\"all\":[\"varexporter\"],\"only\":[\"goto\"],\"id\":\"fp-symfony-varexporter-goto\"},{\"all\":[\"valorapps.com\"],\"only\":[\"idxbuild\"],\"id\":\"fp-easyfolderlisting-changelog\"},{\"all\":[\"matomo.org\"],\"only\":[\"rce\"],\"id\":\"fp-matomo-rce\"},{\"all\":[\"namespace tracy\"],\"only\":[\"phtml\"],\"id\":\"fp-tracy-phtml\"},{\"all\":[\"guzzlehttp\",\"requestfsm\"],\"only\":[\"goto\"],\"id\":\"fp-guzzle-requestfsm\"},{\"all\":[\"siteguarding.com\",\"siteguarding_server_ip1\"],\"only\":[\"feed:upload-shell-uname-form\"],\"id\":\"fp-siteguarding-agent\"},{\"all\":[\"muruguard\"],\"only\":[\"feed:helix-ultimate-xss\"],\"id\":\"fp-muruguard-scanner\"},{\"all\":[\"<svg\"],\"not\":[\"<script\",\"<?php\",\"<?=\",\"onload=\",\"onerror=\",\"onmouseover=\",\"onclick=\",\"onfocus=\",\"javascript:\",\"<foreignobject\"],\"only\":[\"tmp_exec\"],\"id\":\"fp-benign-svg-tmp\"}],\"seo\":{\"weights\":[],\"keywords\":[],\"sigs\":[]},\"recall\":[],\"fetched\":\"2026-07-31 00:02:41\",\"fetched_ts\":1785610638,\"etag\":\"\\\"6a6b92d9-1e99\\\"\",\"modified\":\"Thu, 30 Jul 2026 18:07:21 GMT\"},\"htp_incidents\":[]}'
WHERE `type` = 'component' AND `element` = 'com_htprotect'
| Status | Duration |
|---|
| Starting | 2.41 ms |
| checking permissions | 0.03 ms |
| Opening tables | 0.06 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init for update | 0.29 ms |
| Updating | 0.79 ms |
| End of update loop | 0.01 ms |
| Waiting for query cache lock | 0.01 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.68 ms |
| Query end | 0.02 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.01 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.02 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.01 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 9 | JDatabaseDriverMysqli->execute() | JROOT/administrator/components/com_htprotect/core/defs.php:3837 |
| 8 | HtpDefs::saveCached() | JROOT/administrator/components/com_htprotect/core/defs.php:1023 |
| 7 | HtpDefs::refresh() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3195 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 2.50 ms Na de laatste zoekopdracht: 2.82 ms Zoekopdracht geheugen: 0.161 MB geheugen voor zoekopdracht: 28.406 MB Regels teruggegeven: 1
SELECT `params`
FROM `hmclx_extensions`
WHERE `type` = 'component'
AND `element` = 'com_htprotect'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_extensions | ref | element_clientid,element_folder_clientid,extension | element_clientid | 402 | const | 1 | Using index condition; Using where |
| Status | Duration |
|---|
| Starting | 0.12 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.04 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.10 ms |
| Optimizing | 0.07 ms |
| Statistics | 0.28 ms |
| Preparing | 0.05 ms |
| Executing | 0.01 ms |
| Sending data | 0.71 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.01 ms |
| closing tables | 0.02 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.01 ms |
| Freeing items | 0.02 ms |
| Updating status | 2.95 ms |
| Reset for next command | 0.02 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 10 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 9 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_htprotect/core/defs.php:2169 |
| 8 | HtpDefs::loadMalwareCached() | JROOT/administrator/components/com_htprotect/core/defs.php:1111 |
| 7 | HtpDefs::refreshMalwareSigs() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3207 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.86 ms Na de laatste zoekopdracht: 5.72 ms Zoekopdracht geheugen: 0.020 MB geheugen voor zoekopdracht: 28.481 MB Regels teruggegeven: 1
Identieke zoekopdrachten:
#78SELECT `rules`
FROM `hmclx_assets`
WHERE `id` = 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_assets | const | PRIMARY | PRIMARY | 4 | const | 1 | |
| Status | Duration |
|---|
| Starting | 0.10 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.06 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.02 ms |
| init | 0.06 ms |
| Optimizing | 0.03 ms |
| Statistics | 0.11 ms |
| Preparing | 0.00 ms |
| Unlocking tables | 0.01 ms |
| Preparing | 0.02 ms |
| Executing | 0.01 ms |
| Sending data | 0.02 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 10 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 9 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_htprotect/core/accounts.php:449 |
| 8 | HtpAccounts::privilegedGroupIds() | JROOT/administrator/components/com_htprotect/core/accounts.php:563 |
| 7 | HtpAccounts::suspiciousAdmins() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3258 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.44 ms Na de laatste zoekopdracht: 0.21 ms Zoekopdracht geheugen: 0.020 MB geheugen voor zoekopdracht: 28.486 MB Regels teruggegeven: 2
Identieke zoekopdrachten:
#79SELECT DISTINCT `user_id`
FROM `hmclx_user_usergroup_map`
WHERE `group_id` IN (8)
LIMIT 500
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_user_usergroup_map | range | NULL | PRIMARY | 8 | NULL | 8 | Using where; Using index for group-by; Using temporary |
| Status | Duration |
|---|
| Starting | 0.05 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.01 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.04 ms |
| Preparing | 0.01 ms |
| Creating tmp table | 0.06 ms |
| Executing | 0.00 ms |
| Sending data | 0.06 ms |
| Removing tmp table | 0.01 ms |
| Sending data | 0.01 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 9 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1550 |
| 8 | JDatabaseDriver->loadColumn() | JROOT/administrator/components/com_htprotect/core/accounts.php:575 |
| 7 | HtpAccounts::suspiciousAdmins() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3258 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.01 ms Na de laatste zoekopdracht: 0.29 ms Zoekopdracht geheugen: 0.020 MB geheugen voor zoekopdracht: 28.491 MB Regels teruggegeven: 2
SELECT `id`,`username`,`name`,`email`,`registerDate`,`lastvisitDate`,`block`
FROM `hmclx_users`
WHERE `id` IN (613,800)
LIMIT 500
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_users | range | PRIMARY | PRIMARY | 4 | NULL | 2 | Using where |
| Status | Duration |
|---|
| Starting | 0.07 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.03 ms |
| Optimizing | 0.02 ms |
| Statistics | 0.04 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.06 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 9 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1506 |
| 8 | JDatabaseDriver->loadAssocList() | JROOT/administrator/components/com_htprotect/core/accounts.php:594 |
| 7 | HtpAccounts::suspiciousAdmins() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3258 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.41 ms Na de laatste zoekopdracht: 0.37 ms Zoekopdracht geheugen: 0.020 MB geheugen voor zoekopdracht: 28.495 MB Regels teruggegeven: 1
SELECT `id`,`name`,`types`,`area`,`plugins`,`params`
FROM `hmclx_wf_profiles`
WHERE `published` = 1
LIMIT 200
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_wf_profiles | ALL | NULL | INDEX KEY ONTBREEKT | NULL | NULL | 5 | Using where |
| Status | Duration |
|---|
| Starting | 0.06 ms |
| checking permissions | 0.00 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.00 ms |
| System lock | 0.00 ms |
| table lock | 0.00 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.01 ms |
| Preparing | 0.01 ms |
| Executing | 0.00 ms |
| Sending data | 0.05 ms |
| End of update loop | 0.00 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.01 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.02 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 9 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1506 |
| 8 | JDatabaseDriver->loadAssocList() | JROOT/administrator/components/com_htprotect/core/defs.php:3390 |
| 7 | HtpDefs::checkJceProfiles() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3280 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.06 ms Na de laatste zoekopdracht: 11.92 ms Zoekopdracht geheugen: 0.021 MB geheugen voor zoekopdracht: 28.498 MB Regels teruggegeven: 1
SELECT `params`
FROM `hmclx_users`
WHERE `email` = 'pch.info@dubbelbit.nl'
LIMIT 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_users | ref | email | email | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.24 ms |
| checking permissions | 0.02 ms |
| Opening tables | 0.05 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.06 ms |
| Optimizing | 0.03 ms |
| Statistics | 0.18 ms |
| Preparing | 0.04 ms |
| Executing | 0.01 ms |
| Sending data | 0.10 ms |
| End of update loop | 0.01 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 11 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 10 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_htprotect/core/maillang.php:86 |
| 9 | HtpMailLang::tag() | JROOT/administrator/components/com_htprotect/core/maillang.php:167 |
| 8 | HtpMailLang::load() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3489 |
| 7 | PlgSystemHtprotectwatch->notify() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3294 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 1.14 ms Na de laatste zoekopdracht: 0.32 ms Zoekopdracht geheugen: 0.021 MB geheugen voor zoekopdracht: 28.504 MB Regels teruggegeven: 1
SELECT `params`
FROM `hmclx_extensions`
WHERE `element` = 'com_languages'
LIMIT 1
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_extensions | ref | element_clientid,element_folder_clientid | element_clientid | 402 | const | 1 | Using index condition |
| Status | Duration |
|---|
| Starting | 0.07 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.01 ms |
| Statistics | 0.09 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.05 ms |
| End of update loop | 0.00 ms |
| Query end | 0.01 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.00 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 11 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 10 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_htprotect/core/maillang.php:111 |
| 9 | HtpMailLang::tag() | JROOT/administrator/components/com_htprotect/core/maillang.php:167 |
| 8 | HtpMailLang::load() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3489 |
| 7 | PlgSystemHtprotectwatch->notify() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3294 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.93 ms Na de laatste zoekopdracht: 4.51 ms Zoekopdracht geheugen: 0.161 MB geheugen voor zoekopdracht: 28.509 MB Regels teruggegeven: 1
SELECT `params`
FROM `hmclx_extensions`
WHERE `type` = 'component'
AND `element` = 'com_htprotect'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_extensions | ref | element_clientid,element_folder_clientid,extension | element_clientid | 402 | const | 1 | Using index condition; Using where |
| Status | Duration |
|---|
| Starting | 0.11 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.05 ms |
| Optimizing | 0.03 ms |
| Statistics | 0.13 ms |
| Preparing | 0.04 ms |
| Executing | 0.00 ms |
| Sending data | 0.14 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.01 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.01 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.05 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 11 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 10 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_htprotect/core/watch.php:1242 |
| 9 | HtpWatch::loadNotified() | JROOT/administrator/components/com_htprotect/core/watch.php:348 |
| 8 | HtpWatch::recordNotification() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3502 |
| 7 | PlgSystemHtprotectwatch->notify() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3294 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 0.56 ms Na de laatste zoekopdracht: 1.77 ms Zoekopdracht geheugen: 0.161 MB geheugen voor zoekopdracht: 28.514 MB Regels teruggegeven: 1
SELECT `params`
FROM `hmclx_extensions`
WHERE `type` = 'component'
AND `element` = 'com_htprotect'
| id | select_type | table | type | possible_keys | key | key_len | ref | rows | Extra |
|---|
| 1 | SIMPLE | hmclx_extensions | ref | element_clientid,element_folder_clientid,extension | element_clientid | 402 | const | 1 | Using index condition; Using where |
| Status | Duration |
|---|
| Starting | 0.06 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.02 ms |
| After opening tables | 0.01 ms |
| System lock | 0.01 ms |
| table lock | 0.01 ms |
| init | 0.02 ms |
| Optimizing | 0.02 ms |
| Statistics | 0.08 ms |
| Preparing | 0.02 ms |
| Executing | 0.00 ms |
| Sending data | 0.10 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.00 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.03 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 11 | JDatabaseDriverMysqli->execute() | JROOT/libraries/joomla/database/driver.php:1740 |
| 10 | JDatabaseDriver->loadResult() | JROOT/administrator/components/com_htprotect/core/watch.php:1280 |
| 9 | HtpWatch::saveNotified() | JROOT/administrator/components/com_htprotect/core/watch.php:348 |
| 8 | HtpWatch::recordNotification() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3502 |
| 7 | PlgSystemHtprotectwatch->notify() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3294 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
Tijd zoekopdracht: 2.47 ms Na de laatste zoekopdracht: 3.01 ms Zoekopdracht geheugen: 0.005 MB geheugen voor zoekopdracht: 29.050 MB
Identieke zoekopdrachten:
#84UPDATE `hmclx_extensions`
SET `params` = '{\"htp_shield\":{\"site_path\":\"\",\"sef_rules\":1,\"api_router\":1,\"api_mode\":\"route\",\"fastcgi_auth\":1,\"apache_options\":1,\"follow_symlink\":0,\"force_https\":1,\"www_mode\":0,\"canonical_host\":\"\",\"h_frame\":1,\"h_nosniff\":1,\"h_referrer\":\"strict-origin-when-cross-origin\",\"h_poweredby\":1,\"h_hsts\":0,\"h_hsts_sub\":0,\"h_coop\":0,\"h_permissions\":0,\"f_query\":1,\"f_rfi\":1,\"f_methods\":1,\"f_wpnoise\":1,\"htaccess_external\":0,\"shield_autoheal\":1,\"shield_autoheal_last\":0,\"mig_selfon_2415\":1,\"guard_dismissed\":0,\"x_shield\":1,\"x_sigs_off\":[],\"defs_version\":\"2026-07-15.9ac386\",\"mal_whitelist\":[],\"u_harden\":1,\"u_dirs\":[\"images\",\"media\"],\"emergency_lock\":0,\"notify_email\":\"pch.info@dubbelbit.nl\",\"notify_reminder_days\":14,\"unsub_secret\":\"knIOkiU01E3ceU0YZZ8ARjTQkWuTbqXAfktb1qjg6K0\",\"unsub_base\":\"https:\\/\\/www.efitec.nl\\/\",\"site_fp\":\"6d83c72d155aaa19f87ab9edd8cf222657b5b548\",\"swarm_contrib_id\":\"\",\"swarm_acked\":[],\"watch_manifest\":{\".htaccess\":\"dcb97f95087f2bdb336d0ffdcc300371ca6c4c51\",\"administrator\\/.htaccess\":\"2a00152a7d76a1d4a9444edf477c7404821a8b08\",\"images\\/.htaccess\":\"69714eb0929213f686d66baa144fceefbb395f8f\",\"media\\/.htaccess\":\"69714eb0929213f686d66baa144fceefbb395f8f\"},\"core_manifest\":{\"index.php\":\"2f1b60fc565276ae146bea9aaeadec93fb4dc87c\",\"administrator\\/index.php\":\"7078c5d7b2181900c509c93302f324e2dae228bf\"},\"core_jversion\":\"3.10.12\",\"accounts_watch\":1,\"account_baseline\":{\"613\":{\"id\":613,\"username\":\"admin\",\"email\":\"pch.info@dubbelbit.nl\",\"phash\":\"6300584d05e69c7f07ba2fb51a2f5ade41aeedd4\",\"block\":0,\"lastvisit\":\"2026-07-15 10:54:36\",\"pneeds\":0},\"800\":{\"id\":800,\"username\":\"dubbelbit\",\"email\":\"info@dubbelbit.nl\",\"phash\":\"081a5bae87c5a349a57ac9416a5157be4b8f95d5\",\"block\":0,\"lastvisit\":\"2025-11-06 17:15:16\",\"pneeds\":0}},\"admin_whitelist\":[],\"helix_ignore\":[],\"seo_watch\":1,\"compat_guard\":1,\"seo_cloaking_auto\":0,\"seo_whitelist\":[],\"seo_topic_ack\":[],\"seo_baseline\":{\"title\":\"Home\",\"out_domains\":{\"www.facebook.com\":1,\"nl.pinterest.com\":1,\"www.youtube.com\":1,\"www.s-bb.nl\":1,\"nieuw.efitec.nl\":1,\"xdebug.org\":1},\"shingles\":{\"511079512\":1,\"2918310184\":1,\"155886152\":1,\"3160688592\":1,\"3485062088\":1,\"585239104\":1,\"3828873704\":1,\"4087449296\":1,\"3631890208\":1,\"2453473432\":1,\"352088384\":1,\"1507055824\":1,\"1387258184\":1,\"96078016\":1,\"4120744744\":1,\"884599352\":1,\"148068952\":1,\"2322729328\":1,\"1647395640\":1,\"550572240\":1,\"2804985368\":1,\"2665301464\":1,\"3371643872\":1,\"1999195856\":1,\"412108984\":1,\"3675484672\":1,\"2196848680\":1,\"2599037872\":1,\"4081499304\":1,\"187337984\":1,\"362962264\":1,\"2094558736\":1,\"2787016200\":1,\"1792673952\":1,\"3358772584\":1,\"3190343216\":1,\"2235320368\":1,\"4225413856\":1,\"148784336\":1,\"4133289600\":1,\"1990767144\":1,\"265081816\":1,\"1454988472\":1,\"3545206312\":1,\"2836836760\":1,\"1552018832\":1,\"344452216\":1,\"461581872\":1,\"202494824\":1,\"3735037840\":1,\"3332537384\":1,\"2554787144\":1,\"746144872\":1,\"1848356288\":1,\"3951814824\":1,\"1464161728\":1,\"982788704\":1,\"3748426760\":1,\"136372440\":1,\"3214585776\":1,\"1332842344\":1,\"1366336928\":1,\"754226368\":1,\"1993946344\":1,\"140539032\":1,\"3458701480\":1,\"1779788808\":1,\"829495128\":1,\"258726864\":1,\"2313381704\":1,\"506576576\":1,\"682230128\":1,\"2799752896\":1,\"1200023392\":1,\"1387821168\":1,\"3867735952\":1,\"235572904\":1,\"211001480\":1,\"1209613064\":1,\"1950179312\":1,\"39928272\":1,\"2520740096\":1,\"810676984\":1,\"1550852192\":1,\"3946537872\":1,\"1061088320\":1,\"924937024\":1,\"2981285080\":1,\"4214313248\":1,\"2706907200\":1,\"4109595712\":1,\"2467453096\":1,\"1925217168\":1,\"254204696\":1,\"2797136096\":1,\"3557110600\":1,\"4041208904\":1,\"1327249520\":1,\"1607673584\":1,\"4007425464\":1,\"2632851624\":1,\"3330990656\":1,\"2693581640\":1,\"689915416\":1,\"4066896848\":1,\"480467872\":1,\"3008275536\":1,\"3101468488\":1,\"172199312\":1,\"650342624\":1,\"2553018880\":1,\"2609132040\":1,\"2991890336\":1,\"3462925544\":1,\"2964742568\":1,\"357174032\":1,\"1561660688\":1,\"1048480240\":1,\"1489547928\":1,\"208422712\":1,\"3778160000\":1,\"3789275216\":1,\"2776431456\":1,\"507422944\":1,\"4101744904\":1,\"942566752\":1,\"3196827536\":1,\"648166736\":1,\"1094268640\":1,\"1260128512\":1,\"3590796976\":1,\"1273715136\":1,\"4239054088\":1,\"1559046784\":1,\"4007417480\":1,\"7730296\":1,\"1458451704\":1,\"2911589176\":1,\"454621680\":1,\"1251844592\":1,\"4015838272\":1,\"1300147528\":1,\"1236487296\":1,\"3294019280\":1,\"4123225216\":1,\"670221008\":1,\"2571777288\":1,\"3627078176\":1,\"293222816\":1,\"281163600\":1,\"2508087208\":1,\"3543193024\":1,\"1915969656\":1,\"717056536\":1,\"848595304\":1,\"3107900104\":1,\"2589595704\":1,\"2034508136\":1,\"1977429088\":1,\"2584638584\":1,\"2493542936\":1,\"1158834928\":1,\"1531644320\":1,\"4102387360\":1,\"39764600\":1,\"4261163824\":1,\"1123389784\":1,\"2094010560\":1,\"1856123928\":1,\"376102376\":1,\"4096007544\":1,\"2256249280\":1,\"1618392856\":1,\"2709313920\":1,\"444641888\":1,\"3013023016\":1,\"4217705304\":1,\"2214186752\":1,\"716719120\":1,\"1972556728\":1,\"2438508112\":1,\"1820085032\":1,\"1223539912\":1,\"2846665840\":1,\"933003528\":1,\"2230427152\":1,\"1208455864\":1,\"2025534160\":1,\"1408784776\":1,\"2685059296\":1,\"3489792648\":1,\"1615724560\":1,\"8044840\":1,\"2316854528\":1,\"2550915448\":1,\"1211668720\":1,\"1935561680\":1,\"1828019016\":1,\"1827743704\":1,\"1337666672\":1,\"1911606592\":1,\"3178569384\":1,\"2552993816\":1,\"2123798152\":1,\"3761658400\":1,\"548688272\":1,\"2129684000\":1,\"4124423392\":1,\"1153004272\":1,\"796890520\":1,\"1247028480\":1,\"958748368\":1,\"1744512424\":1,\"647816080\":1,\"743882928\":1,\"3084540200\":1,\"3651199344\":1,\"109843936\":1,\"3303788176\":1,\"3393712720\":1,\"2772452800\":1,\"1345583752\":1,\"4138023008\":1,\"1630734352\":1,\"1587613576\":1,\"1950652592\":1,\"2777296976\":1,\"2621186584\":1,\"36106456\":1,\"2825573424\":1,\"303059736\":1,\"955024752\":1,\"4174757896\":1,\"335870296\":1,\"947878136\":1,\"885775072\":1,\"2836090264\":1,\"1479167544\":1,\"3195444184\":1,\"1373515616\":1,\"2703441304\":1,\"2999798000\":1,\"807202496\":1,\"2139078408\":1,\"3679148440\":1,\"4128820280\":1,\"4051291288\":1,\"524040760\":1,\"3226643448\":1,\"3914545768\":1,\"3485632672\":1,\"1455493656\":1,\"3040222736\":1,\"1738075592\":1,\"3987514200\":1,\"428036792\":1,\"2710735120\":1,\"3436957576\":1,\"3230827720\":1,\"1002378832\":1,\"477165832\":1,\"1378722152\":1,\"2798472384\":1,\"272556984\":1,\"351010464\":1,\"2168780672\":1,\"1806222752\":1,\"3716151024\":1,\"209155304\":1,\"2826036216\":1,\"420540632\":1,\"4203005848\":1,\"957468880\":1,\"1728849744\":1,\"4015778440\":1,\"1216866856\":1,\"4007963960\":1,\"3846677624\":1,\"3656753424\":1,\"75803256\":1,\"600705112\":1,\"1859028960\":1,\"2694091560\":1,\"2607914576\":1,\"2834052552\":1,\"3439897368\":1,\"2144818552\":1,\"3130333816\":1,\"3591606896\":1,\"1894249248\":1,\"4188555200\":1,\"245520800\":1,\"1682089672\":1,\"9149544\":1,\"3226699984\":1,\"1372800744\":1,\"2964205104\":1,\"722285192\":1,\"2322851088\":1,\"2139649696\":1,\"603889336\":1,\"3640799032\":1,\"1116378504\":1,\"3895415872\":1,\"1253935208\":1,\"528756504\":1,\"2284709784\":1,\"802473640\":1,\"3733678920\":1,\"361847392\":1,\"1232831160\":1,\"144058216\":1,\"1338885880\":1,\"992984272\":1,\"3773773072\":1,\"4182600\":1,\"2502992360\":1,\"4070217592\":1,\"547683160\":1,\"3290051432\":1,\"79724832\":1,\"821879880\":1,\"3181784208\":1,\"2105835160\":1,\"1048475128\":1,\"1530568368\":1,\"3978930832\":1,\"4141876912\":1,\"3134899488\":1,\"1235858440\":1,\"810201200\":1,\"3515040152\":1,\"2863190304\":1,\"1420257944\":1,\"798171424\":1,\"3843014608\":1,\"610676112\":1,\"1833740312\":1,\"3925377248\":1,\"2006124312\":1,\"3781864704\":1,\"3031336392\":1,\"4137422488\":1,\"3039953848\":1,\"1385104704\":1,\"4245224744\":1,\"4290332968\":1,\"2274655504\":1,\"1645581528\":1,\"2669455816\":1,\"3722712864\":1,\"1646278032\":1,\"2080430464\":1,\"1286501976\":1,\"1591713568\":1,\"1088809128\":1,\"3634194248\":1,\"3615937792\":1,\"3089178208\":1,\"3235297640\":1,\"1552428824\":1,\"1558271616\":1,\"2721862208\":1,\"1872388720\":1,\"1925908336\":1,\"1739818640\":1,\"1067862528\":1,\"4176326200\":1,\"1295895024\":1,\"1416323816\":1,\"252019184\":1,\"673687856\":1,\"1020035096\":1,\"1477984416\":1,\"798794864\":1,\"3895830512\":1,\"3877253568\":1,\"3725099576\":1,\"2100351152\":1,\"2474987096\":1,\"73942424\":1,\"13272208\":1,\"1943482168\":1,\"3977611416\":1,\"1547675656\":1,\"1718305248\":1,\"1732106904\":1,\"1643112200\":1,\"1345094056\":1,\"2907109104\":1,\"1613823168\":1,\"1646322024\":1},\"redirect_to\":\"\",\"ts\":1785610640},\"seo_overview_ts\":1785610637,\"seo_overview_finding\":[],\"core_overview_ts\":1784128054,\"core_overview_finding\":[],\"plugin_initialized\":1,\"quickicon_initialized\":1,\"autosecure\":0,\"autosecure_last\":0,\"tmp_autoclean\":0,\"tmp_keep\":[],\"autoupdate_notify\":0,\"autoupdate_ext\":1,\"autoupdate_all\":0,\"autoupdate_self\":1,\"autoupdate_manual\":0,\"autoupdate_mail_success\":0,\"autoupdate_include\":[],\"autoupdate_keep\":1,\"autoupdate_interval\":86400,\"autoupdate_schedule\":\"daily\",\"autoupdate_hour\":21,\"autoupdate_weekday\":5,\"autoupdate_grace\":3,\"autoupdate_malscan\":1,\"autoupdate_skip_major\":0,\"keep_update_sites\":1,\"keep_update_sites_except\":[],\"s_php\":1,\"s_types\":1,\"s_ext\":\"7z,avif,bmp,br,css,csv,doc,docx,eot,geojson,gif,gml,gpx,gz,htm,html,ico,ics,jp2,jpe,jpeg,jpg,js,json,kml,kmz,m4a,m4v,map,mjs,mov,mp3,mp4,mpeg,mpg,odp,ods,odt,oga,ogg,ogv,opus,otf,pdf,png,ppt,pptx,rar,rtf,svg,svgz,tif,tiff,ttf,txt,vtt,wasm,wav,webm,webmanifest,webp,woff,woff2,xls,xlsx,xml,xsl,zip\",\"s_files\":[\"administrator\\/components\\/com_akeeba\\/restore.php\",\"administrator\\/components\\/com_akeebabackup\\/restore.php\"],\"s_dirs_php\":[\"plugins\\/system\\/bfnetwork\"],\"s_dirs_static\":[],\"allow_paths\":[],\"s_dotfiles\":1,\"s_wellknown\":1,\"s_sensitive\":1,\"s_manifests\":0,\"s_sysdirs\":1,\"s_sysdirs_list\":[\"administrator\\/cache\",\"administrator\\/logs\",\"cache\",\"cli\",\"log\",\"logs\",\"tmp\"],\"p_compress\":1,\"p_precomp\":0,\"p_expires\":1,\"p_etag\":0,\"custom_top\":\"\",\"custom_bottom\":\"\",\"file_sha1\":\"dcb97f95087f2bdb336d0ffdcc300371ca6c4c51\",\"last_written\":\"2026-07-15 17:20:03\",\"last_test\":{\"checks\":[{\"label\":\"Home page reachable\",\"url\":\"https:\\/\\/www.efitec.nl\\/\",\"status\":200,\"ok\":true,\"note\":\"\"},{\"label\":\"Backend reachable (401 = password protection active)\",\"url\":\"https:\\/\\/www.efitec.nl\\/administrator\\/index.php\",\"status\":401,\"ok\":true,\"note\":\"\"},{\"label\":\"PHP shield active (test call is rejected with 403)\",\"url\":\"https:\\/\\/www.efitec.nl\\/htpx-canary-fbfbe897.php\\/htp\",\"status\":403,\"ok\":true,\"note\":\"\"},{\"label\":\"configuration.php blocked\",\"url\":\"https:\\/\\/www.efitec.nl\\/configuration.php\",\"status\":403,\"ok\":true,\"note\":\"\"}],\"regression\":false,\"reason\":\"\",\"time\":\"2026-07-15 15:20:03\"},\"guard_dir\":\"\",\"guard_recover\":\"263c210ee005a46813c42d75dd82d7144cb9b918b4356d8c60a8f9225963fe48\",\"welcome_sent\":1,\"welcome_green_since\":0,\"jed_review_ack\":\"\",\"jed_mail_last\":0,\"htaccess_cap\":[]},\"htp_defs\":{\"schema\":1,\"version\":\"2026-07-31.fa71fe\",\"signatures\":[{\"id\":\"jce-profiles-import\",\"label\":\"JCE Profil-Import (CVE-2026-48907)\",\"label_en\":\"JCE profile import (CVE-2026-48907)\",\"desc\":\"Unauthentifizierter Profil-Import im JCE-Editor - Beginn der aktuellen RCE-Kette (schaltet PHP-Uploads frei). Kein legitimer Frontend-Aufruf.\",\"desc_en\":\"Unauthenticated profile import in the JCE editor - start of the current RCE chain (enables PHP uploads). No legitimate frontend call.\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*task=profiles\\\\.import)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"jce-rpc-upload\",\"label\":\"JCE Webshell-Upload via plugin.rpc (CVE-2026-48907)\",\"label_en\":\"JCE webshell upload via plugin.rpc (CVE-2026-48907)\",\"desc\":\"Datei-Upload \\u00fcber den JCE-Dateibrowser (plugin.rpc, method=upload). Greift nur im Frontend; eingeloggte Autoren (legitimer Editor-Upload) bleiben unber\\u00fchrt.\",\"desc_en\":\"File upload via the JCE file browser (plugin.rpc, method=upload). Applies only
on the frontend; logged-in authors (legitimate editor upload) are unaffected.\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*task=plugin\\\\.rpc)(?=.*method=upload)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":null},{\"id\":\"jce-imgmanager\",\"label\":\"JCE Image Manager (Alt-Exploit)\",\"label_en\":\"JCE Image Manager (legacy exploit)\",\"desc\":\"Klassischer unauthentifizierter Datei-Upload \\u00fcber den JCE-Bildmanager (sehr alte JCE-Versionen).\",\"desc_en\":\"Classic unauthenticated file upload via the JCE image manager (very old JCE versions).\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*plugin=imgmanager)(?=.*method=form)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":null},{\"id\":\"novarain-nrframework\",\"label\":\"Novarain \\/ Tassos Framework (com_ajax include)\",\"label_en\":\"Novarain \\/ Tassos Framework (com_ajax include)\",\"desc\":\"CVE-2026-21627: unauthentifizierte PHP-Datei-Einbindung \\u00fcber plg_system_nrframework via com_ajax (task=include).\",\"desc_en\":\"CVE-2026-21627: unauthenticated PHP file inclusion via plg_system_nrframework through com_ajax (task=include).\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*nrframework)(?=.*task=include)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"astroid-ajax\",\"label\":\"Astroid Framework (AJAX-Endpunkt)\",\"label_en\":\"Astroid Framework (AJAX endpoint)\",\"desc\":\"CVE-2026-21628: ungepr\\u00fcfter Astroid-AJAX-Endpunkt (Upload\\/Installation). Coarse-Match auf com_ajax + astroid.\",\"desc_en\":\"CVE-2026-21628: unchecked Astroid AJAX endpoint (upload\\/installation). Coarse match
on com_ajax + astroid.\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*(plugin|template|view)=astroid)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"helix3-ajax\",\"label\":\"Helix3 (JoomShaper): unauth. com_ajax-Handler (Datei schreiben\\/l\\u00f6schen)\",\"label_en\":\"Helix3 (JoomShaper): unauth com_ajax handler (file write\\/delete)\",\"desc\":\"Helix3 < 3.1.1: der Ajax-Handler onAjaxHelix3 pr\\u00fcfte weder Login noch Rechte. Trifft gezielt die gef\\u00e4hrlichen Unauth-Aktionen im POST-Body: save (Layout-JSON ins aktive Template schreiben), remove (Datei l\\u00f6schen via Path-Traversal), import (Template-Style-Settings \\u00fcberschreiben) sowie upload_image\\/remove_image\\/updateFonts. Legitime Gast-Aktionen (voting, load) und eingeloggte Template-Nutzung \",\"desc_en\":\"Helix3 < 3.1.1: the onAjaxHelix3 ajax handler checked neither login nor permission. Targets the dangerous unauth POST-body actions: save (write layout JSON into the active template), remove (delete a file via path traversal), import (overwrite template style settings) plus upload_image\\/remove_image\\/updateFonts. Legitimate guest actions (voting, load)
and logged-in template use are unaffected. Fix:\",\"default\":1,\"qs\":\"data(?:\\\\[|%5b)action(?:\\\\]|%5d)=(?:save|remove|import|updatefonts)|action=(?:upload_image|remove_image)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"helix3-comajax\",\"label\":\"Helix3 (JoomShaper): unauth. com_ajax-Dispatcher (Datei-Write\\/Delete, Style-Injektion)\",\"label_en\":\"Helix3 (JoomShaper): unauth com_ajax dispatcher (file write\\/delete, style injection)\",\"desc\":\"Helix3 < 3.1.1: der Front-Dispatcher (option=com_ajax mit plugin=helix3) rief onAjaxHelix3 VOR jeder Token-\\/Rechtepr\\u00fcfung auf - unauthentifiziert save\\/import\\/remove\\/resetLayout\\/updateFonts\\/fontVariants (Datei-Schreiben, Path-Traversal-L\\u00f6schen, Template-Style-Injektion, Stored XSS). Blockt jeden GAST-Aufruf dieses Dispatchers im Frontend (Defense-in-Depth, f\\u00e4ngt auch laufende Scans) - erg\\u00e4nzt d\",\"desc_en\":\"Helix3 < 3.1.1: the front-end dispatcher (option=com_ajax with plugin=helix3) invoked onAjaxHelix3 BEFORE any token\\/permission check - unauthenticated save\\/import\\/remove\\/resetLayout\\/updateFonts\\/fontVariants (file write, path-traversal delete, template style injection, stored XSS). Blocks every GUEST call of this dispatcher
on the front end (defense in depth, also catches ongoing scans) - complemen\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*plugin=helix3\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"helixultimate-comajax\",\"label\":\"Helix Ultimate (JoomShaper): unauth. com_ajax-Dispatcher (Men\\u00fc-Write\\/Datei\\/Export)\",\"label_en\":\"Helix Ultimate (JoomShaper): unauth com_ajax dispatcher (menu write\\/file\\/export)\",\"desc\":\"Helix Ultimate < 2.2.7: der com_ajax-Handler onAjaxHelixultimate (option=com_ajax mit plugin=helixultimate, Action im task-Param) lief VOR jeder Login-\\/Rechtepr\\u00fcfung - ein anonymer Angreifer konnte in die Men\\u00fc-Einstellungen schreiben (Stored XSS bis in die Admin-Sitzung), Dateien per Path-Traversal beliebig l\\u00f6schen, einen Open Redirect ausl\\u00f6sen und das Template ungesch\\u00fctzt exportieren. Blockt\",\"desc_en\":\"Helix Ultimate < 2.2.7: the com_ajax handler onAjaxHelixultimate (option=com_ajax with plugin=helixultimate, action in the task param) ran BEFORE any login\\/permission check - an anonymous attacker could write into the menu settings (stored XSS reaching the admin session), delete files anywhere via path traversal, trigger an open redirect
and export the template unprotected. Blocks every GUEST call\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*plugin=helixultimate\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"comajax-include\",\"label\":\"com_ajax: Datei-Einbindung (generisch)\",\"label_en\":\"com_ajax: file inclusion (generic)\",\"desc\":\"F\\u00e4ngt unbekannte LFI-L\\u00fccken derselben Klasse ab: com_ajax mit task=include\\/require. Frontend.\",\"desc_en\":\"Catches unknown LFI holes of the same class: com_ajax with task=include\\/require. Frontend.\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*task=(include|require)(_once)?)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"sppagebuilder-uploadicon\",\"label\":\"SP Page Builder: unauthentifizierter Icon-Upload (RCE)\",\"label_en\":\"SP Page Builder: unauthenticated icon upload (RCE)\",\"desc\":\"Zero-Day in SP Page Builder bis 6.6.1: der asset-Controller (task=asset.uploadCustomIcon) hatte keinerlei Zugriffs-\\/Login-Pr\\u00fcfung - unauthentifizierter Datei-Upload nach \\/media\\/com_sppagebuilder\\/assets\\/iconfont\\/ - RCE. Nur Mini-WAF (G\\u00e4ste), da eingeloggte Builder den Endpunkt legitim nutzen.\",\"desc_en\":\"Zero-day in SP Page Builder up to 6.6.1: the asset controller (task=asset.uploadCustomIcon) had no access\\/login check - unauthenticated file upload to \\/media\\/com_sppagebuilder\\/assets\\/iconfont\\/ - RCE. Mini-WAF only (guests), since logged-in builders use the endpoint legitimately.\",\"default\":1,\"qs\":\"(?=.*option=com_sppagebuilder)(?=.*task=asset\\\\.uploadCustomIcon)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":null},{\"id\":\"dpcalendar-createdby-sqli\",\"label\":\"DPCalendar: unauth. SQL-Injection (Autor-Filter)\",\"label_en\":\"DPCalendar: unauth SQL injection (author filter)\",\"desc\":\"DPCalendar Blind-SQLi (Joomla 4.4-6 < 10.11.2, J3 < 8.19.4): der Frontend-Autor-Filter filter_created_by (option=com_dpcalendar, view=events) floss in skalarer Form ungecastet in a.created_by IN (...) - anonymes Auslesen beliebiger DB-Tabellen (nur lesend). Blockt Gast-Anfragen, deren filter_created_by kein reiner Integer ist (legitim = Autor-IDs\\/Ziffern) -> FP-frei. Fix 10.11.2 \\/ 8.19.4.\",\"desc_en\":\"DPCalendar blind SQLi (Joomla 4.4-6 < 10.11.2, J3 < 8.19.4): the front-end author filter filter_created_by (option=com_dpcalendar, view=events) flowed uncast into a.created_by IN (...) in its scalar form - anonymous read of arbitrary DB tables (read-only). Blocks guest requests whose filter_created_by is not a pure integer (legit = author IDs\\/digits) -> FP-free. Fix 10.11.2 \\/ 8.19.4.\",\"default\":1,\"qs\":\"(?=.*option=com_dpcalendar)(?=.*filter_created_by=[0-9,]*[^0-9,&])\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_dpcalendar\"},{\"id\":\"acym-entityselect-sqli\",\"label\":\"AcyMailing: unauth. SQL-Injection (Entity-Select Spaltenliste)\",\"label_en\":\"AcyMailing: unauth SQL injection (entity-select column list)\",\"desc\":\"CVE-2026-56292 (AcyMailing 6.0.0-10.11.0): der Frontend-Endpunkt EntitySelectController::loadEntityFront (option=com_acym, task=loadEntityFront) nahm die Request-Parameter columns\\/join_table ungeprueft in die SELECT-Spaltenliste von UserClass::getMatchingElements auf - ein anonymer Besucher konnte per Subquery beliebige DB-Tabellen (inkl. Passwort-Hashes) auslesen. Blockt GAST-Aufrufe dieses Tasks\",\"desc_en\":\"CVE-2026-56292 (AcyMailing 6.0.0-10.11.0): the front-end endpoint EntitySelectController::loadEntityFront (option=com_acym, task=loadEntityFront) placed the request parameters columns\\/join_table unchecked into the SELECT column list of UserClass::getMatchingElements - an anonymous visitor could read arbitrary DB tables (incl. password hashes) via a subquery. Blocks GUEST calls of this task whose c\",\"default\":1,\"qs\":\"(?=.*option=com_acym)(?=.*task=loadEntityFront)(?=.*(?:columns|join_table|join)=[^&]*(?:\\\\(|%28|%2528|\\\\s|%20|\\\\+))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_acym\"},{\"id\":\"quix-article-sqli\",\"label\":\"Quix Page Builder: unauth. SQL-Injection (Einzel-Artikel-AJAX)\",\"label_en\":\"Quix Page Builder: unauth SQL injection (single-article AJAX)\",\"desc\":\"Quix (ThemeXpert, Free UND Pro) bis 6.2.0, inkl. der 5.x-Reihe: der oeffentliche AJAX-Endpunkt (option=com_quix, task=ajax, element=joomla-article) ruft QuixJoomlaArticleElement::getAjax() ohne Login-\\/Token-\\/Lizenz-Pruefung; die Artikel-ID kommt base64-kodiert im data-Parameter und wird in articleExist() UNGECASTET in die DB-Query konkateniert -> unauthentifizierte, fehler-basierte SQL-Injection (\",\"desc_en\":\"Quix (ThemeXpert, Free
AND Pro) up to 6.2.0, incl. the 5.x line: the public AJAX endpoint (option=com_quix, task=ajax, element=joomla-article) calls QuixJoomlaArticleElement::getAjax() with no login\\/token\\/license check; the article id arrives base64-encoded in the data parameter
and is concatenated UNCAST into the DB query in articleExist() -> unauthenticated error-based SQL injection (CVSS 8.7). \",\"default\":1,\"qs\":\"(?=.*option=com_quix)(?=.*task=ajax\\\\b)(?=.*element=joomla-article\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_quix\"},{\"id\":\"joomcck-tags-sqli\",\"label\":\"JoomCCK: unauth. SQL-Injection (Tag-Verwaltung)\",\"label_en\":\"JoomCCK: unauth SQL injection (tag management)\",\"desc\":\"CVE-2026-49048 (JoomCCK 6.x vor 6.4.1): der Front-End-Task tags.save\\/tags.delete (option=com_joomcck) lief OHNE Token-\\/Login-\\/Rechte-Pruefung und schob den Request-Parameter tag (getString) roh - mit Double-Quote-Ausbruch - in ZWEI aufeinanderfolgende SQL-Statements (Existenz-SELECT + UPDATE). Ein anonymer Besucher konnte die Datenbank auslesen und veraendern (stacked\\/error-based SQLi). Blockt jed\",\"desc_en\":\"CVE-2026-49048 (JoomCCK 6.x before 6.4.1): the front-end task tags.save\\/tags.delete (option=com_joomcck) ran with NO token\\/login\\/permission check
and concatenated the request parameter tag (getString) raw - with a double-quote breakout - into TWO consecutive SQL statements (existence SELECT + UPDATE). An anonymous visitor could read
and modify the database (stacked\\/error-based SQLi). Blocks every \",\"default\":1,\"qs\":\"(?=.*option=com_joomcck)(?=.*task=tags\\\\.(?:save|delete))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_joomcck\"},{\"id\":\"gridbox-store-register\",\"label\":\"Balbooa Gridbox: unauth. Konto-Erstellung (store.register)\",\"label_en\":\"Balbooa Gridbox: unauth account creation (store.register)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, gemeldet 2026-07-28, Fix in 2.20.2 (29.07.2026). Der Front-End-Task store.register lief OHNE Login\\/Token und legte ein Joomla-Konto mit FREI WAEHLBARER Usergruppe plus sofort gueltiger Session an (unauth Privilege Escalation). Blockt jeden Gast-Aufruf dieses Tasks. Kosten: falls die Site die Gridbox-eigene Frontend-Registrierung nu\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to
and incl. 2.20.1 - actively exploited, reported 2026-07-28, fixed in 2.20.2 (29 Jul 2026). The front-end task store.register ran WITHOUT login\\/token
and created a Joomla account with an ARBITRARY usergroup plus an immediately valid session (unauth privilege escalation). Blocks every guest call of this task. Cost: if the site uses Gridbox front-end registration (\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=store(\\\\.|%2e)register)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":\"com_gridbox\"},{\"id\":\"gridbox-uploader-showimage-read\",\"label\":\"Balbooa Gridbox: unauth. Datei-Lesen (uploader.showImage)\",\"label_en\":\"Balbooa Gridbox: unauth arbitrary file read (uploader.showImage)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, Fix in 2.20.2 (29.07.2026). Der Front-End-Task uploader.showImage laed ohne Login den Query-Parameter image= und gibt bei Nicht-Bildern die Datei roh aus (fopen+fpassthru) -> unauth Arbitrary File Read, u. a. configuration.php. Trifft JEDE Gridbox-Installation. SURGICAL: greift NUR, wenn image= ein Angriffsmuster enthaelt (Pfad-Kle\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to
and incl. 2.20.1 - actively exploited, fixed in 2.20.2 (29 Jul 2026). The front-end task uploader.showImage reads the query parameter image= without login
and, for non-images, dumps the file raw (fopen+fpassthru) -> unauth arbitrary file read incl. configuration.php. Hits EVERY Gridbox install. SURGICAL: fires ONLY when image= contains an attack pattern (travers\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=uploader(\\\\.|%2e)showImage)(?=.*image=(?:%2f|\\/|[a-z]:|[a-z]%3a|[^&]*(?:\\\\.\\\\.|%2e%2e|\\\\.php|%2ephp|%00|php:|php%3a|:%2f%2f|:\\/\\/)))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":\"com_gridbox\"},{\"id\":\"gridbox-uploader-savephoto\",\"label\":\"Balbooa Gridbox: unauth. Datei-Schreiben (uploader.savePhotoEditorImage)\",\"label_en\":\"Balbooa Gridbox: unauth arbitrary file write (uploader.savePhotoEditorImage)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, Fix in 2.20.2 (29.07.2026). Der Front-End-Task uploader.savePhotoEditorImage schreibt eine beliebige Datei (inkl. .php) in den Webroot; der Zieldateiname liegt im POST-Body (php:\\/\\/input) und ist fuer die .htaccess unsichtbar, und eingeloggte Redakteure nutzen den Endpunkt legitim. Daher waf_only + scope=guest: NUR im Echtzeit-Plugi\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to
and incl. 2.20.1 - actively exploited, fixed in 2.20.2 (29 Jul 2026). The front-end task uploader.savePhotoEditorImage writes an arbitrary file (incl. .php) into the webroot; the target filename is in the POST body (php:\\/\\/input), invisible to .htaccess,
and logged-in editors use the endpoint legitimately. Hence waf_only + scope=guest: enforced ONLY in the real-t\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=uploader(\\\\.|%2e)savePhotoEditorImage)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_gridbox\"},{\"id\":\"baforms-signature-rce\",\"label\":\"Balbooa Forms: unauth. RCE (Signature-Feld, CVE-2026-65880)\",\"label_en\":\"Balbooa Forms: unauth RCE (signature field, CVE-2026-65880)\",\"desc\":\"Balbooa Forms (com_baforms) bis inkl. 2.4.2.1 - CVE-2026-65880 (CVSS 10.0), aktiv ausgenutzt, Fix erst 2.4.3. Beim Absenden eines Formulars mit SIGNATURE-Feld (task=form.sendMessage) verwendet FormModel::saveSignature den vom Angreifer im Feld-JSON gelieferten Funktionsnamen dynamisch als aufgerufene Funktion mit angeh\\u00e4ngtem Wert - unauthentifizierte Remote Code Execution. Der legitime Wert ist i\",\"desc_en\":\"Balbooa Forms (com_baforms) up to
and incl. 2.4.2.1 - CVE-2026-65880 (CVSS 10.0), actively exploited, fixed only in 2.4.3. Submitting a form with a SIGNATURE field (task=form.sendMessage) makes FormModel::saveSignature use the attacker-supplied function name
from the field JSON dynamically as the called function with an appended value - unauthenticated remote code execution. The legitimate value i\",\"default\":1,\"qs\":\"(?=.*\\\\bmethod[^a-z0-9]{1,6}(?:system|exec|shell_exec|passthru|assert|popen|proc_open|pcntl_exec|file_get_contents|readfile|show_source|highlight_file|fopen|scandir|phpinfo|eval|create_function|call_user_func)\\\\b)(?=.*\\\\bimage\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":1,\"trigger\":\"com_baforms\"},{\"id\":\"traversal-encoded\",\"label\":\"Pfad-Klettern (kodierte Varianten)\",\"label_en\":\"Path traversal (encoded variants)\",\"desc\":\"Erg\\u00e4nzt den Standard-Filter um Umgehungstricks: ....\\/\\/ , doppelte Kodierung (%252e), %c0%ae, %2e%2e%5c.\",\"desc_en\":\"Extends the standard filter with bypass tricks: ....\\/\\/ , double encoding (%252e), %c0%ae, %2e%2e%5c.\",\"default\":1,\"qs\":\"(\\\\.{3,}\\/|%252e|%c0%a[ef]|%2e%2e%5c|\\\\.\\\\.%5c)\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"php-wrapper-uri\",\"label\":\"PHP-Stream-Wrapper im Pfad\",\"label_en\":\"PHP stream wrapper in the path\",\"desc\":\"Blockiert php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ , expect:\\/\\/ u. a. direkt im angefragten Pfad.\",\"desc_en\":\"Blocks php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ , expect:\\/\\/ etc. directly in the requested path.\",\"default\":1,\"qs\":null,\"uri\":\"(?:php|phar|data|expect|glob|zlib|zip):\\/\",\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"api-config-leak\",\"label\":\"Joomla-API Konfigurations-Leak\",\"label_en\":\"Joomla API configuration leak\",\"desc\":\"CVE-2023-23752: sch\\u00fctzt den Endpunkt \\/api\\/...\\/v1\\/config\\/application auch ohne komplette API-Sperre.\",\"desc_en\":\"CVE-2023-23752: protects the \\/api\\/...\\/v1\\/config\\/application endpoint even without a complete API block.\",\"default\":1,\"qs\":null,\"uri\":\"^api\\/index\\\\.php\\/v[0-9]+\\/config\",\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"php-object-injection\",\"label\":\"PHP Object Injection (serialisierte Payload)\",\"label_en\":\"PHP object injection (serialised payload)\",\"desc\":\"Serialisiertes PHP-Objekt in einem Parameter (O:\\/C:<L\\u00e4nge>:) - typischer Einstieg f\\u00fcr Object-Injection\\/POP-Ketten. Kommt in normalen Anfragen nicht vor.\",\"desc_en\":\"Serialised PHP object in a parameter (O:\\/C:<length>:) - typical entry point for object injection\\/POP chains. Does not occur in normal requests.\",\"default\":1,\"qs\":\"(?<![a-z0-9])[oc]:[0-9]{1,4}:\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"stream-wrapper-param\",\"label\":\"PHP-Stream-Wrapper in Parameter\",\"label_en\":\"PHP stream wrapper in a parameter\",\"desc\":\"php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ u. a. als Parameterwert - LFI\\/RCE-Vektor. Erg\\u00e4nzt die Pfad-Variante (php-wrapper-uri).\",\"desc_en\":\"php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ etc. as a parameter value - LFI\\/RCE vector. Complements the path variant (php-wrapper-uri).\",\"default\":1,\"qs\":\"(php|phar|data|expect|glob|zlib|zip):\\/{2}\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"param-traversal\",\"label\":\"Pfad-Klettern im Parameter\",\"label_en\":\"Path traversal in a parameter\",\"desc\":\"Mehrfaches ..\\/ als Parameterwert - generisches Directory-Traversal\\/LFI in beliebigen Komponenten.\",\"desc_en\":\"Repeated ..\\/ as a parameter value - generic directory traversal\\/LFI in any component.\",\"default\":1,\"qs\":\"=(\\\\.\\\\.\\/){2,}\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null}],\"vuln_extensions\":[{\"element\":\"aimycaptchalessformguard\",\"type\":\"plugin\",\"folder\":\"captcha\",\"name\":\"Aimy Captcha-Less Form Guard\",\"below\":\"20.1\",\"above\":\"17.0\",\"severity\":\"high\",\"note\":\"Sicherheitsl\\u00fccke in 18.0 bis 20.0, vom Hersteller in 20.1 behoben (freie und PRO-Edition betroffen). Kein Workaround - auf Aimy Captcha-Less Form Guard 20.1 oder neuer aktualisieren.\",\"note_en\":\"Security issue in 18.0 to 20.0, fixed by the vendor in 20.1 (free
and PRO edition affected). No workaround - update to Aimy Captcha-Less Form Guard 20.1 or newer.\",\"advisory\":\"https:\\/\\/www.aimy-extensions.com\\/joomla\\/captcha-less-form-guard.html\",\"advisory_en\":\"https:\\/\\/www.aimy-extensions.com\\/joomla\\/captcha-less-form-guard.html\"},{\"element\":\"com_easystore\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EasyStore (JoomShaper)\",\"below\":\"2.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere unauthentifizierte SQL-Injections (CVE-2026-65759 ff.). Auf EasyStore 2.0.2 oder neuer aktualisieren.\",\"note_en\":\"Multiple unauthenticated SQL injections (CVE-2026-65759 ff.). Update to EasyStore 2.0.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65759\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65759\"},{\"element\":\"com_splms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP LMS (JoomShaper)\",\"below\":\"4.1.4\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-48909: unauth. Code-Ausf\\u00fchrung durch unsichere Cookie-Deserialisierung. Auf SP LMS 4.1.4 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48909: unauthenticated code execution via insecure cookie deserialization. Update to SP LMS 4.1.4 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-48909\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-48909\"},{\"element\":\"com_osmembership\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Membership Pro (JoomDonation)\",\"below\":\"4.6.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-62415: kritische L\\u00fccke durch unsichere Standardkonfiguration. Auf Membership Pro 4.6.2 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-62415: critical flaw caused by an insecure default configuration. Update to Membership Pro 4.6.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-62415\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-62415\"},{\"element\":\"com_convertforms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Convert Forms (Tassos)\",\"below\":\"5.2.3\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische L\\u00fccken bis 5.2.2 (Datei-L\\u00f6schung, Datenleck; CVE-2024-40744). Auf Convert Forms 5.2.3 oder neuer aktualisieren.\",\"note_en\":\"Multiple critical flaws up to 5.2.2 (arbitrary file deletion, data exposure; CVE-2024-40744). Update to Convert Forms 5.2.3 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2024-40744\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2024-40744\"},{\"element\":\"sourcerer\",\"type\":\"plugin\",\"folder\":\"editors-xtd\",\"name\":\"Sourcerer (Regular Labs)\",\"below\":\"12.2.9\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2025-22204: Code-Injection durch mangelnde Rechtepr\\u00fcfung. Auf Sourcerer 12.2.9 oder neuer aktualisieren.\",\"note_en\":\"CVE-2025-22204: code injection due to missing permission checks. Update to Sourcerer 12.2.9 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-22204\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-22204\"},{\"element\":\"com_easydiscuss\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EasyDiscuss (StackIdeas)\",\"below\":\"5.0.16\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-21625: ACL-Umgehung im JSON-Output (Zugriff auf gesch\\u00fctzte Forendaten). Auf EasyDiscuss 5.0.16 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21625: access-control bypass in the JSON output exposing protected forum data. Update to EasyDiscuss 5.0.16 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-21625\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-21625\"},{\"element\":\"com_komento\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Komento (StackIdeas)\",\"below\":\"4.0.8\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2025-54294: SQL-Injection, ausnutzbar durch unprivilegierte Nutzer. Auf Komento 4.0.8 oder neuer aktualisieren.\",\"note_en\":\"CVE-2025-54294: SQL injection exploitable by unprivileged users. Update to Komento 4.0.8 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-54294\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-54294\"},{\"element\":\"nrframework\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Novarain \\/ Tassos Framework\",\"below\":\"6.0.38\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-21627: unauthentifizierte PHP-Einbindung via com_ajax. Auf 6.0.38 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21627: unauthenticated PHP inclusion via com_ajax. Update to 6.0.38 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/joomla-tassos-framework-novarain-framework-sicherheitsluecke\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/joomla-tassos-framework-novarain-framework-sicherheitsluecke\"},{\"element\":\"astroid\",\"type\":\"library\",\"folder\":\"\",\"name\":\"Astroid Framework\",\"below\":\"3.3.11\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-21628: unauthentifizierter Datei-Upload via AJAX-Endpunkt (Dropper in \\/images\\/). Auf 3.3.13 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21628: unauthenticated file upload via AJAX endpoint (dropper in \\/images\\/). Update to 3.3.13 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/joomla-astroid-framework-sicherheitsluecke-vulnerability\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/joomla-astroid-framework-sicherheitsluecke-vulnerability\"},{\"element\":\"helix3\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Helix3 (JoomShaper)\",\"below\":\"3.1.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Unauthentifizierter com_ajax-Handler (onAjaxHelix3) ohne Login-\\/Rechtepr\\u00fcfung: Angreifer k\\u00f6nnen Dateien ins aktive Template schreiben oder per Path-Traversal l\\u00f6schen (save\\/remove\\/import). Auf Helix3 3.1.1 oder neuer aktualisieren.\",\"note_en\":\"Unauthenticated com_ajax handler (onAjaxHelix3) with no login or permission check: attackers can write files into the active template or delete files via path traversal (save\\/remove\\/import). Update to Helix3 3.1.1 or newer.\",\"advisory\":\"https:\\/\\/htprotect.org\\/helix3\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/helix3\"},{\"element\":\"helixultimate\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Helix Ultimate (JoomShaper)\",\"below\":\"2.2.7\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Kritische unauth. L\\u00fccke in ALLEN Versionen < 2.2.7: der com_ajax-Handler onAjaxHelixultimate lief VOR jeder Rechtepr\\u00fcfung - anonym in die Men\\u00fcs schreiben (Stored XSS in den Admin), Path-Traversal-L\\u00f6schen, Open Redirect, Template-Export. Auf 2.2.7 updaten (Plugin UND Template). HTProtects Mini-WAF blockt den Aufruf bereits. NICHT mit Helix3 verwechseln.\",\"note_en\":\"Critical unauth flaw in ALL versions below 2.2.7: the com_ajax handler onAjaxHelixultimate ran before any permission check - anonymous menu writes (stored XSS reaching the admin), path-traversal delete, open redirect, template export. Update to 2.2.7 (plugin
AND template). HTProtect mini-WAF already blocks the call. Not to be confused with Helix3.\",\"advisory\":\"https:\\/\\/htprotect.org\\/helix-ultimate\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/helix-ultimate\"},{\"element\":\"com_baforms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Balbooa Forms\",\"below\":\"2.4.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Aktiver Zero-Day (RCE), ALLE Versionen bis 2.4.0: der Upload-Endpoint form.uploadAttachmentFile pr\\u00fcft weder Login\\/Token noch Dateityp - ein anonymer Angreifer kann eine PHP-Datei hochladen und ausf\\u00fchren. NOCH KEIN Patch. Sofortma\\u00dfnahme: Upload-Formulare depublizieren. HTProtects Gast-Upload-Schutz blockt den ausf\\u00fchrbaren Upload bereits.\",\"note_en\":\"Active zero-day (RCE), ALL versions up to 2.4.0: the upload endpoint form.uploadAttachmentFile checks neither login\\/token nor file type - an anonymous attacker can upload
and run a PHP file. NO patch yet. Interim: unpublish forms with upload fields. The HTProtect guest-upload filter already blocks the executable upload.\",\"advisory\":\"https:\\/\\/htprotect.org\\/balbooa-forms\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/balbooa-forms\"},{\"element\":\"com_jce\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JCE Editor\",\"below\":\"2.9.99.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-48907: unauthentifizierter Webshell-Upload (profiles.import + plugin.rpc). Dringend auf JCE 2.9.99.6 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48907: unauthenticated webshell upload (profiles.import + plugin.rpc). Urgently update to JCE 2.9.99.6 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/jce-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/jce-sicherheitsluecke-joomla\"},{\"element\":\"com_rsfiles\",\"type\":\"component\",\"folder\":\"\",\"name\":\"RSFiles!\",\"below\":\"1.17.12\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Aktiver unauthentifizierter Datei-Upload -> RCE, ALLE Versionen bis 1.17.11: der Frontend-Upload (task=rsfiles.upload) pr\\u00fcft weder Login\\/Token noch Dateiendung - ein anonymer Angreifer l\\u00e4dt eine .php nach \\/downloads bzw. \\/briefcase und f\\u00fchrt sie aus. Dringend auf 1.17.12 aktualisieren. HTProtects Gast-Upload-Schutz blockt den ausf\\u00fchrbaren Upload bereits.\",\"note_en\":\"Active unauthenticated file upload -> RCE, ALL versions up to 1.17.11: the front-end upload (task=rsfiles.upload) checks neither login\\/token nor file extension - an anonymous attacker uploads a .php into \\/downloads or \\/briefcase
and executes it. Update to 1.17.12 urgently. The HTProtect guest-upload filter already blocks the executable upload.\",\"advisory\":\"https:\\/\\/www.rsjoomla.com\\/blog\\/view\\/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html\",\"advisory_en\":\"https:\\/\\/www.rsjoomla.com\\/blog\\/view\\/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html\"},{\"element\":\"com_edocman\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EDocman\",\"below\":\"3.9\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Unauthentifizierte SQL-Injection (alle Versionen bis 3.8): ein anonymer Besucher schleust ueber einen Filter-Parameter eines oeffentlichen Frontend-Endpunkts SQL in eine ungequotete DB-Abfrage ein und kann die Datenbank auslesen (bis hin zu Zugangsdaten). Der genaue Vektor ist bewusst nicht veroeffentlicht. Dringend auf EDocman 3.9.0 aktualisieren.\",\"note_en\":\"Unauthenticated SQL injection (all versions up to 3.8): an anonymous visitor injects SQL through a filter parameter of a public front-end endpoint into an unquoted DB query
and can read the database (up to credentials). The exact vector is deliberately undisclosed. Update to EDocman 3.9.0 urgently.\",\"advisory\":\"https:\\/\\/joomdonation.com\\/forum\\/edocman\\/82813-edocman-3-9-0-security-release---important-update-recommended.html\",\"advisory_en\":\"https:\\/\\/joomdonation.com\\/forum\\/edocman\\/82813-edocman-3-9-0-security-release---important-update-recommended.html\"},{\"element\":\"com_foranalytics\",\"type\":\"component\",\"folder\":\"\",\"name\":\"4Analytics\",\"below\":\"5.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Zwei unauthentifizierte Sicherheitsluecken (CVE-2026-57833 + CVE-2026-58077) in ALLEN Versionen vor 5.0.2 - ein anonymer Angreifer braucht keinen Login. Hersteller Weeblr stuft beide als kritisch ein; technische Details sind 7 Tage embargoed. Dringend auf 4Analytics 5.0.2 aktualisieren (laeuft auf Joomla 3-6).\",\"note_en\":\"Two unauthenticated security flaws (CVE-2026-57833 + CVE-2026-58077) in ALL versions before 5.0.2 - an anonymous attacker needs no login. Vendor Weeblr rates both critical; technical details are under a 7-day embargo. Update to 4Analytics 5.0.2 urgently (runs
on Joomla 3-6).\",\"advisory\":\"https:\\/\\/weeblr.com\\/blog\\/critical-vulnerabilities-2026-07-15\",\"advisory_en\":\"https:\\/\\/weeblr.com\\/blog\\/critical-vulnerabilities-2026-07-15\"},{\"element\":\"com_quix\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Quix\",\"below\":\"6.2.1\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Unauthentifizierte SQL-Injection (Free UND Pro, alle Versionen vor 6.2.1 \\u2013 auch die 5.x-Reihe): ein anonymer Besucher kann die gesamte Datenbank auslesen (CVSS 8.7). HTProtects Mini-WAF blockt den Angriff bereits aktiv. Auf Quix 6.2.1 aktualisieren (Free erh\\u00e4lt 6.2.1 ebenfalls \\u00fcber die Update-Funktion).\",\"note_en\":\"Unauthenticated SQL injection (Free
AND Pro, all versions below 6.2.1 \\u2013 including the 5.x line): an anonymous visitor can read the entire database (CVSS 8.7). HTProtect\'s mini-WAF already actively blocks the attack. Update to Quix 6.2.1 (Free receives 6.2.1 too via the update function).\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/quix-sql-injection-disclosure\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/quix-sql-injection-disclosure\\/\"},{\"element\":\"com_joomcck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JoomCCK\",\"below\":\"6.4.1\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"Unauthentifizierte SQL-Injection (CVE-2026-49048, JoomCCK 6.x vor 6.4.1): der Front-End-Task \\u201eTag speichern\\/l\\u00f6schen\\\" pr\\u00fcfte weder Login noch Token und \\u00fcbernahm den Parameter \\u201etag\\\" ungefiltert in zwei SQL-Abfragen - ein anonymer Besucher konnte die Datenbank auslesen und ver\\u00e4ndern. HTProtects Mini-WAF blockt den unautorisierten Gast-Aufruf bereits aktiv. Dringend auf JoomCCK 6.4.1 aktualisi\",\"note_en\":\"Unauthenticated SQL injection (CVE-2026-49048, JoomCCK 6.x before 6.4.1): the front-end \\\"save\\/delete tag\\\" task checked neither login nor token
and took the \\\"tag\\\" parameter unfiltered into two SQL queries - an anonymous visitor could read
and modify the database. HTProtect\'s mini-WAF already actively blocks the unauthorized guest call. Update to JoomCCK 6.4.1 urgently.\",\"advisory\":\"https:\\/\\/github.com\\/JoomCoder-com\\/JoomCCK\\/releases#release-6.4.1\",\"advisory_en\":\"https:\\/\\/github.com\\/JoomCoder-com\\/JoomCCK\\/releases#release-6.4.1\"},{\"element\":\"com_chronoforms8\",\"type\":\"component\",\"folder\":\"\",\"name\":\"ChronoForms\",\"below\":\"8.0.53\",\"above\":\"8.0.0\",\"severity\":\"high\",\"note\":\"Unauthentifizierte gespeicherte XSS (CVE-2026-58148, ChronoForms 8.x vor 8.0.53): ein anonymer Besucher schleust \\u00fcber ein Formular-Feld JavaScript ein, das ungefiltert gespeichert und sp\\u00e4ter - z. B. beim Ansehen der Einsendungen im Backend - ausgef\\u00fchrt wird, bis hin zur \\u00dcbernahme der Admin-Sitzung (CVSS 8.7). Auf ChronoForms 8.0.53 aktualisieren.\",\"note_en\":\"Unauthenticated stored XSS (CVE-2026-58148, ChronoForms 8.x before 8.0.53): an anonymous visitor injects JavaScript via a form field that is stored unfiltered
and later executed - e.g. when viewing the submissions in the backend - up to takeover of the admin session (CVSS 8.7). Update to ChronoForms 8.0.53.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-58148\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-58148\"},{\"element\":\"com_jdownloads\",\"type\":\"component\",\"folder\":\"\",\"name\":\"jDownloads\",\"below\":\"4.1.6\",\"above\":\"4.1.0\",\"severity\":\"high\",\"note\":\"Unauthentifizierte Datei-Upload-L\\u00fccke (jDownloads 4.1.0-4.1.5): eine verwaiste Uploader-Datei (upload-handler.php) pr\\u00fcft weder Login noch Token und l\\u00e4sst einen anonymen Besucher beliebige Dateien - u. a. exe\\/msi\\/Archive - in einen Ordner der Site schreiben; auf manchen Servern bis zur Codeausf\\u00fchrung, sonst Malware-Hosting\\/Speicher-Flutung. HTProtects .htaccess-Schutzschild blockt den direkten \",\"note_en\":\"Unauthenticated file upload flaw (jDownloads 4.1.0-4.1.5): a leftover uploader file (upload-handler.php) checks neither login nor token
and lets an anonymous visitor write arbitrary files - incl. exe\\/msi\\/archives - into a folder
on the site; up to remote code execution
on some servers, otherwise malware hosting \\/ disk flooding. HTProtect\'s .htaccess shield already blocks direct access to the file \",\"advisory\":\"https:\\/\\/www.jdownloads.com\\/index.php\\/news\\/jdownloads-4-1-6-secure-update-released.html\",\"advisory_en\":\"https:\\/\\/www.jdownloads.com\\/index.php\\/news\\/jdownloads-4-1-6-secure-update-released.html\"},{\"element\":\"com_dpcalendar\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DPCalendar\",\"below\":\"10.11.2\",\"above\":\"9.0.0\",\"severity\":\"high\",\"note\":\"DPCalendar (Joomla 4.4-6, 9.0.0-10.11.1): unauthentifizierte Blind-SQL-Injection - der Autor-Filter filter_created_by (Frontend view=events) floss in skalarer Form ohne Integer-Cast in die Query (a.created_by IN ...); ein anonymer Besucher kann beliebige DB-Tabellen AUSLESEN (nichts \\u00e4ndern). Dringend auf 10.11.2 aktualisieren. HTProtects Mini-WAF blockt die Injektion bereits.\",\"note_en\":\"DPCalendar (Joomla 4.4-6, 9.0.0-10.11.1): unauthenticated blind SQL injection - the author filter filter_created_by (front-end view=events) flowed uncast (scalar form) into the query (a.created_by IN ...); an anonymous visitor can READ arbitrary DB tables (no writes). Update to 10.11.2 urgently. HTProtect mini-WAF already blocks the injection.\",\"advisory\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\",\"advisory_en\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\"},{\"element\":\"com_dpcalendar\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DPCalendar\",\"below\":\"8.19.4\",\"above\":\"8.18.0\",\"severity\":\"high\",\"note\":\"DPCalendar Joomla-3-Linie (8.x), 8.18.0-8.19.3: dieselbe unauth Blind-SQL-Injection \\u00fcber den Autor-Filter filter_created_by (skalar, ohne Integer-Cast, nur lesend). In 8.19.4 (Joomla-3-Fix) behoben. Auf 8.19.4 aktualisieren. HTProtects Mini-WAF blockt die Injektion bereits.\",\"note_en\":\"DPCalendar Joomla 3 line (8.x), 8.18.0-8.19.3: same unauth blind SQL injection via the author filter filter_created_by (scalar, no integer cast, read-only). Fixed in 8.19.4 (Joomla 3 fix). Update to 8.19.4. HTProtect mini-WAF already blocks the injection.\",\"advisory\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\",\"advisory_en\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\"},{\"element\":\"com_phocadownload\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Download\",\"below\":\"6.1.3\",\"above\":\"6.0.0\",\"severity\":\"high\",\"note\":\"Authentifizierter Datei-Upload -> RCE (Versionen 6.0 bis 6.1.2): ein eingeloggter Nutzer mit Zugriff auf die Upload-Funktion kann eine ausf\\u00fchrbare Datei (z. B. .php) hochladen und ausf\\u00fchren. In 6.1.3 (Security-Release) behoben - auf 6.1.3 oder neuer aktualisieren. HTProtects PHP-Schild verhindert die Ausf\\u00fchrung einer hochgeladenen PHP-Datei in den Upload-Ordnern bereits.\",\"note_en\":\"Authenticated file upload -> RCE (versions 6.0 to 6.1.2): a logged-in user with access to the upload feature can upload
and run an executable file (e.g. .php). Fixed in 6.1.3 (security release) - update to 6.1.3 or newer. The HTProtect PHP shield already prevents execution of an uploaded PHP file in the upload folders.\",\"advisory\":\"https:\\/\\/www.phoca.cz\\/news\\/1481-phoca-download-version-6-1-3-released-security-release\",\"advisory_en\":\"https:\\/\\/www.phoca.cz\\/news\\/1481-phoca-download-version-6-1-3-released-security-release\"},{\"element\":\"com_phocamaps\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Maps\",\"below\":\"6.1.0\",\"above\":\"5.0.0\",\"severity\":\"medium\",\"note\":\"CVE-2026-65763: reflektiertes XSS (5.0.0-6.0.4) durch unzureichende Eingabepr\\u00fcfung - ein Angreifer bringt einen Besucher \\u00fcber einen pr\\u00e4parierten Link dazu, eingeschleustes JavaScript auszuf\\u00fchren. Auf Phoca Maps 6.1.0 (Security-Release) oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-65763: reflected XSS (5.0.0-6.0.4) via improper input validation - an attacker lures a visitor with a crafted link to run injected JavaScript. Update to Phoca Maps 6.1.0 (security release) or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65763\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65763\"},{\"element\":\"com_phocaguestbook\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Guestbook\",\"below\":\"6.1.1\",\"above\":\"5.0.0\",\"severity\":\"medium\",\"note\":\"CVE-2026-65762: reflektiertes XSS (5.0.0-6.1.0) durch unzureichende Eingabepr\\u00fcfung - ein pr\\u00e4parierter Link f\\u00fchrt beim Besucher eingeschleustes JavaScript aus. Auf Phoca Guestbook 6.1.1 (Security-Release) oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-65762: reflected XSS (5.0.0-6.1.0) via improper input validation - a crafted link runs injected JavaScript in the visitor\'s browser. Update to Phoca Guestbook 6.1.1 (security release) or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65762\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65762\"},{\"element\":\"com_acym\",\"type\":\"component\",\"folder\":\"\",\"name\":\"AcyMailing 6+\",\"below\":\"10.11.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"AcyMailing Neuauflage (6+): CVE-2026-56292 unauthentifizierte SQL-Injection (6.0.0-10.11.0) - ein anonymer Angreifer liest beliebige DB-Tabellen inkl. Passwort-Hashes (CVSS 8.7). \\u00c4ltere L\\u00fccken: CVE-2023-28731 unauth Upload\\/RCE unter 8.3.0, CVE-2026-3614 Rechteausweitung 9.11.0-10.8.1. Dringend auf 10.11.1 aktualisieren.\",\"note_en\":\"AcyMailing new line (6+): CVE-2026-56292 unauthenticated SQL injection (6.0.0-10.11.0) - an anonymous attacker reads arbitrary DB tables incl. password hashes (CVSS 8.7). Older holes: CVE-2023-28731 unauth upload\\/RCE below 8.3.0, CVE-2026-3614 privilege escalation 9.11.0-10.8.1. Update to 10.11.1 urgently.\",\"advisory\":\"https:\\/\\/htprotect.org\\/acymailing\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/acymailing\"},{\"element\":\"com_acymailing\",\"type\":\"component\",\"folder\":\"\",\"name\":\"AcyMailing Classic\",\"below\":\"4.9.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"AcyMailing Classic (End-of-Life): \\u00e4ltere Versionen mit kritischen L\\u00fccken - unauthentifizierter Datei-Upload der 3.x-\\u00c4ra (RCE, z. B. 3.9.0) sowie Backend-SQL-Injection CVE-2015-7338 (in 4.9.5 behoben). Auf eine unterst\\u00fctzte AcyMailing-Version migrieren. (Die 5.x-Linie hat keine bekannte sehr kritische L\\u00fccke; CSV-Injection CVE-2018-9107 in 5.9.1-5.9.5 ist niedrig\\/client-seitig.)\",\"note_en\":\"AcyMailing Classic (end-of-life): older versions with critical holes - unauthenticated file upload of the 3.x era (RCE, e.g. 3.9.0)
and backend SQL injection CVE-2015-7338 (fixed in 4.9.5). Migrate to a supported AcyMailing version. (The 5.x line has no known very critical hole; CSV injection CVE-2018-9107 in 5.9.1-5.9.5 is low\\/client-side.)\",\"advisory\":\"https:\\/\\/htprotect.org\\/acymailing\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/acymailing\"},{\"element\":\"com_igallery\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Ignite Gallery\",\"below\":\"5.4.1\",\"above\":\"5.0.0\",\"severity\":\"high\",\"note\":\"Ignite Gallery 5.0.0 bis 5.4.0: Stored XSS (hoch) durch fehlendes Output-Escaping beim Hochladen\\/Bearbeiten von Bildern, dazu SSRF (ungefilterte Video-URL) und eine Rechteausweitung beim Download geschuetzter\\/unveroeffentlichter Bilder. Ausnutzbar von Nutzern MIT Upload-\\/Bearbeitungsrecht (Frontend oder Backend). Auf 5.4.1 oder neuer aktualisieren.\",\"note_en\":\"Ignite Gallery 5.0.0 to 5.4.0: stored XSS (high) via missing output escaping when uploading\\/editing images, plus SSRF (unfiltered video URL)
and a privilege escalation when downloading restricted\\/unpublished images. Exploitable by users WITH upload\\/edit permission (frontend or backend). Update to 5.4.1 or newer.\",\"advisory\":\"https:\\/\\/www.ignitegallery.com\\/documentation\\/changelog\",\"advisory_en\":\"https:\\/\\/www.ignitegallery.com\\/documentation\\/changelog\"},{\"element\":\"com_icagenda\",\"type\":\"component\",\"folder\":\"\",\"name\":\"iCagenda\",\"below\":\"4.0.8\",\"above\":\"4.0.0\",\"severity\":\"critical\",\"note\":\"CVE-2026-48939 (4.x-Linie 4.0.0-4.0.7): das Event-Formular (task=submit.submit) pr\\u00fcft nur das CSRF-Token, keine Zugriffsrechte - anonymer Datei-Upload. Voller RCE nur auf Joomla 6 (Core blockt .php nicht mehr); auf Joomla <=5 mildert der Core-Filter, die Zugriffsl\\u00fccke bleibt. Dringend auf 4.0.8 aktualisieren. HTProtects Dateischild verhindert die Ausf\\u00fchrung bereits.\",\"note_en\":\"CVE-2026-48939 (4.x line 4.0.0-4.0.7): the event form (task=submit.submit) checks only the CSRF token, no access rights - anonymous file upload. Full RCE only
on Joomla 6 (core no longer blocks .php);
on Joomla <=5 the core filter mitigates but the access flaw remains. Update to 4.0.8 urgently. The HTProtect file shield already prevents execution.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/icagenda-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/icagenda-sicherheitsluecke-joomla\"},{\"element\":\"com_icagenda\",\"type\":\"component\",\"folder\":\"\",\"name\":\"iCagenda\",\"below\":\"3.9.15\",\"above\":\"3.2.1\",\"severity\":\"critical\",\"note\":\"CVE-2026-48939, 3.x-Linie 3.2.1-3.9.14: dieselbe Zugriffsl\\u00fccke im Event-Formular (task=submit.submit, keine Rechtepr\\u00fcfung, anonymer Datei-Upload). In 3.9.15 (Security-Backport f\\u00fcr Joomla 3) behoben. Dringend auf 3.9.15 aktualisieren. HTProtects Dateischild verhindert die Ausf\\u00fchrung bereits. (Voller RCE v. a. auf Joomla 6.)\",\"note_en\":\"CVE-2026-48939, 3.x line 3.2.1-3.9.14: same access-control flaw in the event form (task=submit.submit, no permission check, anonymous file upload). Fixed in 3.9.15 (security backport for Joomla 3). Update to 3.9.15 urgently. The HTProtect file shield already prevents execution. (Full RCE mainly
on Joomla 6.)\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/icagenda-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/icagenda-sicherheitsluecke-joomla\"},{\"element\":\"com_sppagebuilder\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP Page Builder\",\"below\":\"6.7.1\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"Unauthentifizierte SQL-Injection (CVE-2026-65766) bis Version 6.7.0: ein anonymer Besucher liest \\u00fcber einen ungefilterten Parameter (direction) im Dynamic-Content-Endpunkt beliebige Datenbank-Tabellen aus - bis zu Benutzerkonten, Passwort-Hashes und dem Seiten-Geheimnis (CVSS 8.7). Dazu ein offenes Mail-Relay (CVE-2026-65877): Angreifer verschicken \\u00fcber die Kontaktformular-Addons beliebige E-Mai\",\"note_en\":\"Unauthenticated SQL injection (CVE-2026-65766) up to version 6.7.0: via an unfiltered parameter (direction) in the Dynamic Content endpoint an anonymous visitor can read arbitrary database tables - down to user accounts, password hashes
and the site secret (CVSS 8.7). Plus an open mail relay (CVE-2026-65877): attackers send arbitrary emails with a spoofed sender through the contact-form addons. Up\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/sp-page-builder-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/sp-page-builder-sicherheitsluecke-joomla\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.6\",\"above\":\"3.5.0\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) bis 3.5.10: ein Front-End-Upload-Endpunkt (zum Hinzuf\\u00fcgen von Bildern) pr\\u00fcfte nur das CSRF-Token, aber keine Zugriffsrechte und keinen Dateityp - ein nicht eingeloggter Angreifer konnte eine beliebige Datei (z. B. PHP-Shell) in einen frei w\\u00e4hlbaren Ordner hochladen und ausf\\u00fchren (Remote Code Execution). Dringend auf 3.6.0 aktualisieren. (HTProtects generischer Upload-Sch\",\"note_en\":\"Critical flaw (RCE) up to 3.5.10: a front-end upload endpoint (for adding images) only verified the CSRF token but no access rights
and no file type - an unauthenticated attacker could upload an arbitrary file (e.g. a PHP shell) into a freely chosen folder
and execute it (remote code execution). Update to 3.6.0 urgently. (The HTProtect generic upload protection already blocks the unauthenticated u\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.4.10\",\"above\":\"3.2.0\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) in der Joomla-4-Linie unter 3.4.10: unauthentifizierter Datei-Upload \\u00fcber einen Front-End-Endpunkt (nur CSRF-Token, keine Zugriffs-\\/Typpr\\u00fcfung) - beliebige Datei in frei w\\u00e4hlbaren Ordner hochladbar und ausf\\u00fchrbar. In 3.4.10 (Backport) behoben. Dringend aktualisieren. (HTProtects generischer Upload-Schutz blockt den unauthentifizierten Upload bereits; das Dateischild verh\",\"note_en\":\"Critical flaw (RCE) in the Joomla 4 line below 3.4.10: unauthenticated file upload via a front-end endpoint (CSRF token only, no access\\/type check) - arbitrary file uploadable into a freely chosen folder
and executable. Fixed in 3.4.10 (backport). Update urgently. (The HTProtect generic upload protection already blocks the unauthenticated upload; the file shield additionally prevents execution.)\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.1.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) in der Joomla-3-Linie unter 3.1.1: unauthentifizierter Datei-Upload \\u00fcber einen Front-End-Endpunkt (nur CSRF-Token, keine Zugriffs-\\/Typpr\\u00fcfung) - beliebige Datei in frei w\\u00e4hlbaren Ordner hochladbar und ausf\\u00fchrbar. In 3.1.1 (Backport f\\u00fcr Joomla 3) behoben. Dringend aktualisieren. (HTProtects generischer Upload-Schutz blockt den unauthentifizierten Upload bereits; das Date\",\"note_en\":\"Critical flaw (RCE) in the Joomla 3 line below 3.1.1: unauthenticated file upload via a front-end endpoint (CSRF token only, no access\\/type check) - arbitrary file uploadable into a freely chosen folder
and executable. Fixed in 3.1.1 (backport for Joomla 3). Update urgently. (The HTProtect generic upload protection already blocks the unauthenticated upload; the file shield additionally prevents ex\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_eventbooking\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Events Booking\",\"below\":\"5.8.1\",\"above\":\"5.0\",\"severity\":\"medium\",\"note\":\"Zwei Sicherheitsl\\u00fccken ohne Anmeldung in allen Versionen der 5er-Reihe vor 5.8.1: Erstens konnte jeder anonyme Besucher \\u00fcber die Datei-Upload-Funktion des Anmeldeformulars Dateien auf dem Server ablegen - ohne Konto, ohne Anmeldung und ohne Sicherheitstoken; die Funktion war ab Werk in jeder Installation aktiv. Die abgelegten Dateien lie\\u00dfen sich anschlie\\u00dfend unter einem vorhersehbaren Namen wi\",\"note_en\":\"Two unauthenticated security flaws in all versions of the 5.x line below 5.8.1: First, any anonymous visitor could place files
on the server through the file upload of the registration form - no account, no login, no security token; the feature was enabled by default in every installation. The uploaded files could then be retrieved again under a predictable name. Program files were not allowed in \",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/events-booking-unauthenticated-upload-user-enumeration\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/events-booking-unauthenticated-upload-user-enumeration\\/\"},{\"element\":\"com_djclassifieds\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DJ-Classifieds\",\"below\":\"3.11.2\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Schwerwiegende L\\u00fccke in allen Versionen bis einschlie\\u00dflich 3.11.1: Die Funktion zum Hochladen von Anzeigenbildern nahm Dateien entgegen, ohne dass eine Anmeldung n\\u00f6tig war und ohne die \\u00fcblichen Sicherheitspr\\u00fcfungen. Angreifer konnten dadurch eine Schaddatei auf der Website ablegen und im ung\\u00fcnstigen Fall die Kontrolle \\u00fcber die gesamte Seite \\u00fcbernehmen. Die L\\u00fccke wurde bereits aktiv ausgen\",\"note_en\":\"Serious flaw in all versions up to
and including 3.11.1: the image upload used for classified ads accepted files without requiring a login
and without the usual security checks. This allowed attackers to place a malicious file
on the website
and, in the worst
case, take control of the entire site. The flaw was already being actively exploited before a fix was available. Update to version 3.11.2 or\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/dj-classifieds-unauthenticated-file-upload\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/dj-classifieds-unauthenticated-file-upload\\/\"},{\"element\":\"com_gridbox\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Gridbox\",\"below\":\"2.20.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Balbooa hat in zwei Schritten reagiert: 2.20.1 (20.07.2026) schloss eine kritische Anmelde-L\\u00fccke (CVE-2026-61425), blieb aber unvollst\\u00e4ndig. Erst 2.20.2 (29.07.2026) behebt - laut Hersteller in allen Versionen bis einschlie\\u00dflich 2.20.1 - unbefugten Dateizugriff (Lesen und Schreiben), das rekursive L\\u00f6schen ganzer Ordner, mehrere SQL-Einschleusungen, weitere Umgehungen der Rechtepr\\u00fcfung und Inf\",\"note_en\":\"Balbooa responded in two steps: 2.20.1 (20 Jul 2026) closed a critical authentication flaw (CVE-2026-61425) but was incomplete. Only 2.20.2 (29 Jul 2026) fixes - across all versions up to
and including 2.20.1, per the vendor - unauthorized file access (read
and write), recursive deletion of whole directories, multiple SQL injections, further authorization-check bypasses
and information disclosure.\",\"advisory\":\"https:\\/\\/www.balbooa.com\\/blog\\/gridbox\\/gridbox-2-20-2-security-release\",\"advisory_en\":\"https:\\/\\/www.balbooa.com\\/blog\\/gridbox\\/gridbox-2-20-2-security-release\"}],\"php_min\":\"8.1\",\"fetched\":\"2026-08-01 01:42:25\",\"fetched_ts\":1785615665,\"etag\":\"\\\"6a6d343c-f907\\\"\",\"modified\":\"Fri, 31 Jul 2026 23:48:12 GMT\",\"joomla_latest\":{\"3\":\"3.10.12\",\"4\":\"4.4.14\",\"5\":\"5.4.7\",\"6\":\"6.1.2\"},\"joomla_latest_ts\":1785590511,\"joomla_latest_try\":1785590511},\"htp_malware\":{\"schema\":1,\"version\":\"2026-07-29.671bb5\",\"sigs\":[{\"id\":\"backdoor-prepend-sshkey\",\"all\":[\"auto_prepend_file\",\"authorized_keys\"]},{\"id\":\"cred-stealer-ctfaudit\",\"any\":[\"x-ctf-audit\",\"jlib_audit_gid\"]},{\"id\":\"upload-shell-form\",\"all\":[\"move_uploaded_file\",\"check directory permissions\"]},{\"id\":\"sppb-iconfont-shell\",\"any\":[\"sppbwhoami\"]},{\"id\":\"remote-eval-loader\",\"all\":[\"eval(\\\"?>\\\"\"],\"any\":[\"fetchcontentfromurl\",\"file_get_contents(\\\"http\",\"file_get_contents(\'http\"]},{\"id\":\"seo-doorway-slot\",\"any\":[\"slot gacor\",\"situs slot gacor\"]},{\"id\":\"filemanager-backdoor-data\",\"all\":[\"<?php exit;?>{\",\"\\\"groupinfo\\\"\",\"\\\"sizemax\\\"\"]},{\"id\":\"encrypted-eval-openssl\",\"all\":[\"openssl_raw_data\",\"aes-256-cbc\"],\"not\":[\"openssl_decrypt\",\"openssl_encrypt\"]},{\"id\":\"0xnix-split-encrypted\",\"all\":[\"0xnix encrypted code\"]},{\"id\":\"upload-shell-devco1\",\"all\":[\"move_uploaded_file\",\"devco1\"]},{\"id\":\"upload-shell-uname-form\",\"all\":[\"move_uploaded_file\",\"php_uname\",\"multipart\\/form-data\"]},{\"id\":\"hacktool-adminer\",\"all\":[\"adminer_errors\",\"idf_unescape\"]},{\"id\":\"webshell-range-obfuscator\",\"all\":[\"\\\"r\\\".\\\"a\\\".\\\"n\\\".\\\"g\\\".\\\"e\\\"\",\"eval\"]},{\"id\":\"webshell-md5quad-gate\",\"all\":[\"md5(md5(md5(md5(\",\"eval\"]},{\"id\":\"remote-loader-stream-include\",\"any\":[\"include stream_get_meta_data\",\"require stream_get_meta_data\",\"include(stream_get_meta_data\",\"require(stream_get_meta_data\"]},{\"id\":\"webshell-dual-uploader\",\"all\":[\"remote_url\",\"name=\\\"_upl\\\"\",\"name=\\\"_remote\\\"\"]},{\"id\":\"webshell-comment-obfuscator\",\"all\":[\"-*\\/\\/\\/\",\"\\\"~\\\"\"]},{\"id\":\"eval-openssl-shell\",\"label\":\"eval(openssl_decrypt) webshell\",\"all\":[\"eval(openssl_decrypt(\"]},{\"id\":\"dropper-drivergenius-c2\",\"label\":\"Remote-fetch dropper (drivergenius C2)\",\"all\":[\"drivergenius.it.com\"]},{\"id\":\"dropper-backdate-disguise\",\"label\":\"Remote-fetch dropper (mtime-forge + disguise)\",\"all\":[\"getreferencefiletime\",\"generatefilename\"]},{\"id\":\"js-inject-fake-cleaned\",\"label\":\"JS injection w\\/ fake \\\"cleaned\\/safe\\\" comment\",\"all\":[\"artifacts of previous malicious infection\",\"dangerous code has been removed\"]},{\"id\":\"linkforge-seo-injector\",\"label\":\"LinkForge SEO backlink injector\",\"all\":[\"linkforge.cc\"]},{\"id\":\"seo-doorway-cloak\",\"label\":\"SEO cloaking doorway (Thai gambling, fake sitemap)\",\"all\":[\"output_sitemap_page\",\"is_from_google\",\"send_404_and_exit\"]},{\"id\":\"helix-ultimate-xss\",\"label\":\"Helix Ultimate mega-menu XSS campaign\",\"any\":[\"xss.report\",\"_hu_inject\",\"_huinject\",\"sessionstorage._hxd\"]},{\"id\":\"gsocket-c2\",\"label\":\"gsocket reverse-shell C2 marker\",\"any\":[\"gs_args\"]},{\"id\":\"cloak-engine-thiscitze\",\"label\":\"thiscitze SEO cloaking engine\",\"all\":[\"thiscitze\"]},{\"id\":\"cloak-doorway-jsurl-jumpurl\",\"label\":\"Thai gambling SEO cloaking\\/doorway injector\",\"all\":[\"$js_url\",\"$jump_url\"]},{\"id\":\"cn-aes-loader\",\"label\":\"AES-decrypt + gzinflate eval loader\",\"all\":[\"openssl_decrypt\",\"gzinflate\",\"eval(\\\"?>\\\"\"]},{\"id\":\"cn-loader-tag\",\"label\":\"Chinese \'PHP code security loader\' tag\",\"all\":[\"php\\u4ee3\\u7801\\u5b89\\u5168\\u52a0\\u8f7d\\u5668\"]},{\"id\":\"menu-api-filemanager\",\"label\":\"MENU_API file-manager webshell\",\"all\":[\"menu_api_password\"]},{\"id\":\"remote-eval-curl\",\"label\":\"curl remote-fetch eval loader\",\"all\":[\"eval(\\\"?>\\\"\",\"curl_exec\"]},{\"id\":\"bujang-c2\",\"label\":\"Remote-fetch loader (bujang.online C2)\",\"all\":[\"bujang.online\"]},{\"id\":\"tinyfilemanager-tool\",\"label\":\"Tiny File Manager (webshell-capable file manager)\",\"all\":[\"tinyfilemanager\"]}],\"names\":[{\"id\":\"probe-d1337\",\"m\":[\"_d1337_\"],\"label\":\"d1337 write-access probe \\/ dropper marker\"},{\"id\":\"probe-write-test\",\"m\":[\"_probe_\"],\"label\":\"generic write-access probe marker (_probe_)\"}],\"scan_ext\":[],\"ack\":[\"6608daed700e0afc330788b2a272ca8d\",\"67b5f9a00c7aabf34261c715aeeaadba\",\"9812b693256a0c306cc53368559c7a4b\",\"ec96a3bed6681af996fd37f0818cba6b\",\"abfe3b7513994ae6ac2f33129b5f6e7b\",\"fb2e76c5ebafc2b8ea82e0d35d45fa02\",\"2ec54ce00420cd41dfae5abedc9edcb7\",\"02c1a767857c55d31cae7277bc43bac2\",\"573a5e7374be2925911b552d485a28f3\",\"cdf24443c39d943f8750d4a4420e6581\",\"99af93b919c5b6bc14a82382c39010ec\",\"55e704bb88a8f9ab0d756976c527516b\",\"981b4f5e07bf9cd1249d60d659e4ef93\",\"87d978102ed075a8e58074a0d3595c30\",\"85648deb8324a11400ecaebcfd04ae16\",\"323707d28051b4cbf161420f5f1bb499\",\"19104a261abbdffe7cd1713949b286cf\",\"a72013015988ad7d978ce9841a9668dd\",\"a8af9b93d27c774601e1d8a902145bd7\",\"82c8de717e67a620ca503a1a01a7d909\",\"a8192a3cf6279862054cb3092dad82bf\",\"eae8beb708347cfe54bf87506b572f41\",\"5db6f4cdd20dfee86e05110a2276d748\",\"872e97edc1d4247d2ed86d35f468ff88\",\"da9c67c9b7be2d5a7eb9113d76119abc\",\"d0c5a881e845f93a72e1450259de0d33\",\"ea531694f501221b61a324d3754da603\",\"b8333a512d949684c91c9dd907f9cb0c\",\"2c57aea21d161fe5761ffab0abff8228\",\"93117860cd06939707a4ff1797bebb40\",\"7f58961ebcc0db81b16c2d16072fb084\",\"760423f79cedc17e78df95505e93f0c7\",\"d8b0c0f2faf44495f7954fe826720bad\",\"b9b6b8553113e745ebef3251b5d223b9\",\"3e5d03ecb5de8ab2ff1790d7b78bee24\",\"0cd3f898084fe66b062ab5162d2b370c\",\"deb26b6603b6edd8381f6c77fc53cace\",\"0855cf0d6a33b86a8506aeeb769e4343\",\"bcfa5def6057812cba39996c13c1feb3\",\"b719915e7d46c753fe4aeb7a6b8e7fea\",\"913459ac4f3b49356595a341f9b2ac03\"],\"community\":0,\"fp\":[{\"all\":[\"easycalccheckplus\"],\"only\":[\"rce\"],\"id\":\"ecc-plus-doc-rce\"},{\"all\":[\"phpoffice\\\\phpspreadsheet\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"phpspreadsheet-lib\"},{\"any\":[\"cp_errordocument\",\"status-reason\"],\"not\":[\"<!--#exec\",\"<?\"],\"only\":[\"shtml\"],\"id\":\"plesk-error-shtml\"},{\"all\":[\"gumlet\",\"data:\\/\\/application\\/octet-stream\"],\"only\":[\"wrapper\"],\"id\":\"gumlet-imageresize-datawrapper\"},{\"all\":[\"data:\\/\\/image\",\"exif_read_data\"],\"only\":[\"wrapper\"],\"id\":\"exif-data-wrapper\"},{\"all\":[\"phpoffice\\\\phpword\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"phpword-lib\"},{\"all\":[\"box\\\\spout\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"box-spout-lib\"},{\"all\":[\"sarciszewski\\\\phpfuture\"],\"only\":[\"wrapper\"],\"id\":\"php-future-lib\"},{\"all\":[\"baformsmodelform\"],\"only\":[\"feed:upload-shell-uname-form\"],\"id\":\"fp-baforms-model\"},{\"all\":[\"quixnxt\"],\"only\":[\"goto\"],\"id\":\"fp-quix-goto\"},{\"all\":[\"varexporter\"],\"only\":[\"goto\"],\"id\":\"fp-symfony-varexporter-goto\"},{\"all\":[\"valorapps.com\"],\"only\":[\"idxbuild\"],\"id\":\"fp-easyfolderlisting-changelog\"},{\"all\":[\"matomo.org\"],\"only\":[\"rce\"],\"id\":\"fp-matomo-rce\"},{\"all\":[\"namespace tracy\"],\"only\":[\"phtml\"],\"id\":\"fp-tracy-phtml\"},{\"all\":[\"guzzlehttp\",\"requestfsm\"],\"only\":[\"goto\"],\"id\":\"fp-guzzle-requestfsm\"},{\"all\":[\"siteguarding.com\",\"siteguarding_server_ip1\"],\"only\":[\"feed:upload-shell-uname-form\"],\"id\":\"fp-siteguarding-agent\"},{\"all\":[\"muruguard\"],\"only\":[\"feed:helix-ultimate-xss\"],\"id\":\"fp-muruguard-scanner\"},{\"all\":[\"<svg\"],\"not\":[\"<script\",\"<?php\",\"<?=\",\"onload=\",\"onerror=\",\"onmouseover=\",\"onclick=\",\"onfocus=\",\"javascript:\",\"<foreignobject\"],\"only\":[\"tmp_exec\"],\"id\":\"fp-benign-svg-tmp\"}],\"seo\":{\"weights\":[],\"keywords\":[],\"sigs\":[]},\"recall\":[],\"fetched\":\"2026-07-31 00:02:41\",\"fetched_ts\":1785610638,\"etag\":\"\\\"6a6b92d9-1e99\\\"\",\"modified\":\"Thu, 30 Jul 2026 18:07:21 GMT\"},\"htp_incidents\":[]}'
WHERE `type` = 'component'
AND `element` = 'com_htprotect'
VERKLAREN niet mogelijk voor zoekopdracht: UPDATE `hmclx_extensions`
SET `params` = '{\"htp_shield\":{\"site_path\":\"\",\"sef_rules\":1,\"api_router\":1,\"api_mode\":\"route\",\"fastcgi_auth\":1,\"apache_options\":1,\"follow_symlink\":0,\"force_https\":1,\"www_mode\":0,\"canonical_host\":\"\",\"h_frame\":1,\"h_nosniff\":1,\"h_referrer\":\"strict-origin-when-cross-origin\",\"h_poweredby\":1,\"h_hsts\":0,\"h_hsts_sub\":0,\"h_coop\":0,\"h_permissions\":0,\"f_query\":1,\"f_rfi\":1,\"f_methods\":1,\"f_wpnoise\":1,\"htaccess_external\":0,\"shield_autoheal\":1,\"shield_autoheal_last\":0,\"mig_selfon_2415\":1,\"guard_dismissed\":0,\"x_shield\":1,\"x_sigs_off\":[],\"defs_version\":\"2026-07-15.9ac386\",\"mal_whitelist\":[],\"u_harden\":1,\"u_dirs\":[\"images\",\"media\"],\"emergency_lock\":0,\"notify_email\":\"pch.info@dubbelbit.nl\",\"notify_reminder_days\":14,\"unsub_secret\":\"knIOkiU01E3ceU0YZZ8ARjTQkWuTbqXAfktb1qjg6K0\",\"unsub_base\":\"https:\\/\\/www.efitec.nl\\/\",\"site_fp\":\"6d83c72d155aaa19f87ab9edd8cf222657b5b548\",\"swarm_contrib_id\":\"\",\"swarm_acked\":[],\"watch_manifest\":{\".htaccess\":\"dcb97f95087f2bdb336d0ffdcc300371ca6c4c51\",\"administrator\\/.htaccess\":\"2a00152a7d76a1d4a9444edf477c7404821a8b08\",\"images\\/.htaccess\":\"69714eb0929213f686d66baa144fceefbb395f8f\",\"media\\/.htaccess\":\"69714eb0929213f686d66baa144fceefbb395f8f\"},\"core_manifest\":{\"index.php\":\"2f1b60fc565276ae146bea9aaeadec93fb4dc87c\",\"administrator\\/index.php\":\"7078c5d7b2181900c509c93302f324e2dae228bf\"},\"core_jversion\":\"3.10.12\",\"accounts_watch\":1,\"account_baseline\":{\"613\":{\"id\":613,\"username\":\"admin\",\"email\":\"pch.info@dubbelbit.nl\",\"phash\":\"6300584d05e69c7f07ba2fb51a2f5ade41aeedd4\",\"block\":0,\"lastvisit\":\"2026-07-15 10:54:36\",\"pneeds\":0},\"800\":{\"id\":800,\"username\":\"dubbelbit\",\"email\":\"info@dubbelbit.nl\",\"phash\":\"081a5bae87c5a349a57ac9416a5157be4b8f95d5\",\"block\":0,\"lastvisit\":\"2025-11-06 17:15:16\",\"pneeds\":0}},\"admin_whitelist\":[],\"helix_ignore\":[],\"seo_watch\":1,\"compat_guard\":1,\"seo_cloaking_auto\":0,\"seo_whitelist\":[],\"seo_topic_ack\":[],\"seo_baseline\":{\"title\":\"Home\",\"out_domains\":{\"www.facebook.com\":1,\"nl.pinterest.com\":1,\"www.youtube.com\":1,\"www.s-bb.nl\":1,\"nieuw.efitec.nl\":1,\"xdebug.org\":1},\"shingles\":{\"511079512\":1,\"2918310184\":1,\"155886152\":1,\"3160688592\":1,\"3485062088\":1,\"585239104\":1,\"3828873704\":1,\"4087449296\":1,\"3631890208\":1,\"2453473432\":1,\"352088384\":1,\"1507055824\":1,\"1387258184\":1,\"96078016\":1,\"4120744744\":1,\"884599352\":1,\"148068952\":1,\"2322729328\":1,\"1647395640\":1,\"550572240\":1,\"2804985368\":1,\"2665301464\":1,\"3371643872\":1,\"1999195856\":1,\"412108984\":1,\"3675484672\":1,\"2196848680\":1,\"2599037872\":1,\"4081499304\":1,\"187337984\":1,\"362962264\":1,\"2094558736\":1,\"2787016200\":1,\"1792673952\":1,\"3358772584\":1,\"3190343216\":1,\"2235320368\":1,\"4225413856\":1,\"148784336\":1,\"4133289600\":1,\"1990767144\":1,\"265081816\":1,\"1454988472\":1,\"3545206312\":1,\"2836836760\":1,\"1552018832\":1,\"344452216\":1,\"461581872\":1,\"202494824\":1,\"3735037840\":1,\"3332537384\":1,\"2554787144\":1,\"746144872\":1,\"1848356288\":1,\"3951814824\":1,\"1464161728\":1,\"982788704\":1,\"3748426760\":1,\"136372440\":1,\"3214585776\":1,\"1332842344\":1,\"1366336928\":1,\"754226368\":1,\"1993946344\":1,\"140539032\":1,\"3458701480\":1,\"1779788808\":1,\"829495128\":1,\"258726864\":1,\"2313381704\":1,\"506576576\":1,\"682230128\":1,\"2799752896\":1,\"1200023392\":1,\"1387821168\":1,\"3867735952\":1,\"235572904\":1,\"211001480\":1,\"1209613064\":1,\"1950179312\":1,\"39928272\":1,\"2520740096\":1,\"810676984\":1,\"1550852192\":1,\"3946537872\":1,\"1061088320\":1,\"924937024\":1,\"2981285080\":1,\"4214313248\":1,\"2706907200\":1,\"4109595712\":1,\"2467453096\":1,\"1925217168\":1,\"254204696\":1,\"2797136096\":1,\"3557110600\":1,\"4041208904\":1,\"1327249520\":1,\"1607673584\":1,\"4007425464\":1,\"2632851624\":1,\"3330990656\":1,\"2693581640\":1,\"689915416\":1,\"4066896848\":1,\"480467872\":1,\"3008275536\":1,\"3101468488\":1,\"172199312\":1,\"650342624\":1,\"2553018880\":1,\"2609132040\":1,\"2991890336\":1,\"3462925544\":1,\"2964742568\":1,\"357174032\":1,\"1561660688\":1,\"1048480240\":1,\"1489547928\":1,\"208422712\":1,\"3778160000\":1,\"3789275216\":1,\"2776431456\":1,\"507422944\":1,\"4101744904\":1,\"942566752\":1,\"3196827536\":1,\"648166736\":1,\"1094268640\":1,\"1260128512\":1,\"3590796976\":1,\"1273715136\":1,\"4239054088\":1,\"1559046784\":1,\"4007417480\":1,\"7730296\":1,\"1458451704\":1,\"2911589176\":1,\"454621680\":1,\"1251844592\":1,\"4015838272\":1,\"1300147528\":1,\"1236487296\":1,\"3294019280\":1,\"4123225216\":1,\"670221008\":1,\"2571777288\":1,\"3627078176\":1,\"293222816\":1,\"281163600\":1,\"2508087208\":1,\"3543193024\":1,\"1915969656\":1,\"717056536\":1,\"848595304\":1,\"3107900104\":1,\"2589595704\":1,\"2034508136\":1,\"1977429088\":1,\"2584638584\":1,\"2493542936\":1,\"1158834928\":1,\"1531644320\":1,\"4102387360\":1,\"39764600\":1,\"4261163824\":1,\"1123389784\":1,\"2094010560\":1,\"1856123928\":1,\"376102376\":1,\"4096007544\":1,\"2256249280\":1,\"1618392856\":1,\"2709313920\":1,\"444641888\":1,\"3013023016\":1,\"4217705304\":1,\"2214186752\":1,\"716719120\":1,\"1972556728\":1,\"2438508112\":1,\"1820085032\":1,\"1223539912\":1,\"2846665840\":1,\"933003528\":1,\"2230427152\":1,\"1208455864\":1,\"2025534160\":1,\"1408784776\":1,\"2685059296\":1,\"3489792648\":1,\"1615724560\":1,\"8044840\":1,\"2316854528\":1,\"2550915448\":1,\"1211668720\":1,\"1935561680\":1,\"1828019016\":1,\"1827743704\":1,\"1337666672\":1,\"1911606592\":1,\"3178569384\":1,\"2552993816\":1,\"2123798152\":1,\"3761658400\":1,\"548688272\":1,\"2129684000\":1,\"4124423392\":1,\"1153004272\":1,\"796890520\":1,\"1247028480\":1,\"958748368\":1,\"1744512424\":1,\"647816080\":1,\"743882928\":1,\"3084540200\":1,\"3651199344\":1,\"109843936\":1,\"3303788176\":1,\"3393712720\":1,\"2772452800\":1,\"1345583752\":1,\"4138023008\":1,\"1630734352\":1,\"1587613576\":1,\"1950652592\":1,\"2777296976\":1,\"2621186584\":1,\"36106456\":1,\"2825573424\":1,\"303059736\":1,\"955024752\":1,\"4174757896\":1,\"335870296\":1,\"947878136\":1,\"885775072\":1,\"2836090264\":1,\"1479167544\":1,\"3195444184\":1,\"1373515616\":1,\"2703441304\":1,\"2999798000\":1,\"807202496\":1,\"2139078408\":1,\"3679148440\":1,\"4128820280\":1,\"4051291288\":1,\"524040760\":1,\"3226643448\":1,\"3914545768\":1,\"3485632672\":1,\"1455493656\":1,\"3040222736\":1,\"1738075592\":1,\"3987514200\":1,\"428036792\":1,\"2710735120\":1,\"3436957576\":1,\"3230827720\":1,\"1002378832\":1,\"477165832\":1,\"1378722152\":1,\"2798472384\":1,\"272556984\":1,\"351010464\":1,\"2168780672\":1,\"1806222752\":1,\"3716151024\":1,\"209155304\":1,\"2826036216\":1,\"420540632\":1,\"4203005848\":1,\"957468880\":1,\"1728849744\":1,\"4015778440\":1,\"1216866856\":1,\"4007963960\":1,\"3846677624\":1,\"3656753424\":1,\"75803256\":1,\"600705112\":1,\"1859028960\":1,\"2694091560\":1,\"2607914576\":1,\"2834052552\":1,\"3439897368\":1,\"2144818552\":1,\"3130333816\":1,\"3591606896\":1,\"1894249248\":1,\"4188555200\":1,\"245520800\":1,\"1682089672\":1,\"9149544\":1,\"3226699984\":1,\"1372800744\":1,\"2964205104\":1,\"722285192\":1,\"2322851088\":1,\"2139649696\":1,\"603889336\":1,\"3640799032\":1,\"1116378504\":1,\"3895415872\":1,\"1253935208\":1,\"528756504\":1,\"2284709784\":1,\"802473640\":1,\"3733678920\":1,\"361847392\":1,\"1232831160\":1,\"144058216\":1,\"1338885880\":1,\"992984272\":1,\"3773773072\":1,\"4182600\":1,\"2502992360\":1,\"4070217592\":1,\"547683160\":1,\"3290051432\":1,\"79724832\":1,\"821879880\":1,\"3181784208\":1,\"2105835160\":1,\"1048475128\":1,\"1530568368\":1,\"3978930832\":1,\"4141876912\":1,\"3134899488\":1,\"1235858440\":1,\"810201200\":1,\"3515040152\":1,\"2863190304\":1,\"1420257944\":1,\"798171424\":1,\"3843014608\":1,\"610676112\":1,\"1833740312\":1,\"3925377248\":1,\"2006124312\":1,\"3781864704\":1,\"3031336392\":1,\"4137422488\":1,\"3039953848\":1,\"1385104704\":1,\"4245224744\":1,\"4290332968\":1,\"2274655504\":1,\"1645581528\":1,\"2669455816\":1,\"3722712864\":1,\"1646278032\":1,\"2080430464\":1,\"1286501976\":1,\"1591713568\":1,\"1088809128\":1,\"3634194248\":1,\"3615937792\":1,\"3089178208\":1,\"3235297640\":1,\"1552428824\":1,\"1558271616\":1,\"2721862208\":1,\"1872388720\":1,\"1925908336\":1,\"1739818640\":1,\"1067862528\":1,\"4176326200\":1,\"1295895024\":1,\"1416323816\":1,\"252019184\":1,\"673687856\":1,\"1020035096\":1,\"1477984416\":1,\"798794864\":1,\"3895830512\":1,\"3877253568\":1,\"3725099576\":1,\"2100351152\":1,\"2474987096\":1,\"73942424\":1,\"13272208\":1,\"1943482168\":1,\"3977611416\":1,\"1547675656\":1,\"1718305248\":1,\"1732106904\":1,\"1643112200\":1,\"1345094056\":1,\"2907109104\":1,\"1613823168\":1,\"1646322024\":1},\"redirect_to\":\"\",\"ts\":1785610640},\"seo_overview_ts\":1785610637,\"seo_overview_finding\":[],\"core_overview_ts\":1784128054,\"core_overview_finding\":[],\"plugin_initialized\":1,\"quickicon_initialized\":1,\"autosecure\":0,\"autosecure_last\":0,\"tmp_autoclean\":0,\"tmp_keep\":[],\"autoupdate_notify\":0,\"autoupdate_ext\":1,\"autoupdate_all\":0,\"autoupdate_self\":1,\"autoupdate_manual\":0,\"autoupdate_mail_success\":0,\"autoupdate_include\":[],\"autoupdate_keep\":1,\"autoupdate_interval\":86400,\"autoupdate_schedule\":\"daily\",\"autoupdate_hour\":21,\"autoupdate_weekday\":5,\"autoupdate_grace\":3,\"autoupdate_malscan\":1,\"autoupdate_skip_major\":0,\"keep_update_sites\":1,\"keep_update_sites_except\":[],\"s_php\":1,\"s_types\":1,\"s_ext\":\"7z,avif,bmp,br,css,csv,doc,docx,eot,geojson,gif,gml,gpx,gz,htm,html,ico,ics,jp2,jpe,jpeg,jpg,js,json,kml,kmz,m4a,m4v,map,mjs,mov,mp3,mp4,mpeg,mpg,odp,ods,odt,oga,ogg,ogv,opus,otf,pdf,png,ppt,pptx,rar,rtf,svg,svgz,tif,tiff,ttf,txt,vtt,wasm,wav,webm,webmanifest,webp,woff,woff2,xls,xlsx,xml,xsl,zip\",\"s_files\":[\"administrator\\/components\\/com_akeeba\\/restore.php\",\"administrator\\/components\\/com_akeebabackup\\/restore.php\"],\"s_dirs_php\":[\"plugins\\/system\\/bfnetwork\"],\"s_dirs_static\":[],\"allow_paths\":[],\"s_dotfiles\":1,\"s_wellknown\":1,\"s_sensitive\":1,\"s_manifests\":0,\"s_sysdirs\":1,\"s_sysdirs_list\":[\"administrator\\/cache\",\"administrator\\/logs\",\"cache\",\"cli\",\"log\",\"logs\",\"tmp\"],\"p_compress\":1,\"p_precomp\":0,\"p_expires\":1,\"p_etag\":0,\"custom_top\":\"\",\"custom_bottom\":\"\",\"file_sha1\":\"dcb97f95087f2bdb336d0ffdcc300371ca6c4c51\",\"last_written\":\"2026-07-15 17:20:03\",\"last_test\":{\"checks\":[{\"label\":\"Home page reachable\",\"url\":\"https:\\/\\/www.efitec.nl\\/\",\"status\":200,\"ok\":true,\"note\":\"\"},{\"label\":\"Backend reachable (401 = password protection active)\",\"url\":\"https:\\/\\/www.efitec.nl\\/administrator\\/index.php\",\"status\":401,\"ok\":true,\"note\":\"\"},{\"label\":\"PHP shield active (test call is rejected with 403)\",\"url\":\"https:\\/\\/www.efitec.nl\\/htpx-canary-fbfbe897.php\\/htp\",\"status\":403,\"ok\":true,\"note\":\"\"},{\"label\":\"configuration.php blocked\",\"url\":\"https:\\/\\/www.efitec.nl\\/configuration.php\",\"status\":403,\"ok\":true,\"note\":\"\"}],\"regression\":false,\"reason\":\"\",\"time\":\"2026-07-15 15:20:03\"},\"guard_dir\":\"\",\"guard_recover\":\"263c210ee005a46813c42d75dd82d7144cb9b918b4356d8c60a8f9225963fe48\",\"welcome_sent\":1,\"welcome_green_since\":0,\"jed_review_ack\":\"\",\"jed_mail_last\":0,\"htaccess_cap\":[]},\"htp_defs\":{\"schema\":1,\"version\":\"2026-07-31.fa71fe\",\"signatures\":[{\"id\":\"jce-profiles-import\",\"label\":\"JCE Profil-Import (CVE-2026-48907)\",\"label_en\":\"JCE profile import (CVE-2026-48907)\",\"desc\":\"Unauthentifizierter Profil-Import im JCE-Editor - Beginn der aktuellen RCE-Kette (schaltet PHP-Uploads frei). Kein legitimer Frontend-Aufruf.\",\"desc_en\":\"Unauthenticated profile import in the JCE editor - start of the current RCE chain (enables PHP uploads). No legitimate frontend call.\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*task=profiles\\\\.import)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"jce-rpc-upload\",\"label\":\"JCE Webshell-Upload via plugin.rpc (CVE-2026-48907)\",\"label_en\":\"JCE webshell upload via plugin.rpc (CVE-2026-48907)\",\"desc\":\"Datei-Upload \\u00fcber den JCE-Dateibrowser (plugin.rpc, method=upload). Greift nur im Frontend; eingeloggte Autoren (legitimer Editor-Upload) bleiben unber\\u00fchrt.\",\"desc_en\":\"File upload via the JCE file browser (plugin.rpc, method=upload). Applies only on the frontend; logged-in authors (legitimate editor upload) are unaffected.\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*task=plugin\\\\.rpc)(?=.*method=upload)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":null},{\"id\":\"jce-imgmanager\",\"label\":\"JCE Image Manager (Alt-Exploit)\",\"label_en\":\"JCE Image Manager (legacy exploit)\",\"desc\":\"Klassischer unauthentifizierter Datei-Upload \\u00fcber den JCE-Bildmanager (sehr alte JCE-Versionen).\",\"desc_en\":\"Classic unauthenticated file upload via the JCE image manager (very old JCE versions).\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*plugin=imgmanager)(?=.*method=form)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":null},{\"id\":\"novarain-nrframework\",\"label\":\"Novarain \\/ Tassos Framework (com_ajax include)\",\"label_en\":\"Novarain \\/ Tassos Framework (com_ajax include)\",\"desc\":\"CVE-2026-21627: unauthentifizierte PHP-Datei-Einbindung \\u00fcber plg_system_nrframework via com_ajax (task=include).\",\"desc_en\":\"CVE-2026-21627: unauthenticated PHP file inclusion via plg_system_nrframework through com_ajax (task=include).\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*nrframework)(?=.*task=include)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"astroid-ajax\",\"label\":\"Astroid Framework (AJAX-Endpunkt)\",\"label_en\":\"Astroid Framework (AJAX endpoint)\",\"desc\":\"CVE-2026-21628: ungepr\\u00fcfter Astroid-AJAX-Endpunkt (Upload\\/Installation). Coarse-Match auf com_ajax + astroid.\",\"desc_en\":\"CVE-2026-21628: unchecked Astroid AJAX endpoint (upload\\/installation). Coarse match on com_ajax + astroid.\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*(plugin|template|view)=astroid)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"helix3-ajax\",\"label\":\"Helix3 (JoomShaper): unauth. com_ajax-Handler (Datei schreiben\\/l\\u00f6schen)\",\"label_en\":\"Helix3 (JoomShaper): unauth com_ajax handler (file write\\/delete)\",\"desc\":\"Helix3 < 3.1.1: der Ajax-Handler onAjaxHelix3 pr\\u00fcfte weder Login noch Rechte. Trifft gezielt die gef\\u00e4hrlichen Unauth-Aktionen im POST-Body: save (Layout-JSON ins aktive Template schreiben), remove (Datei l\\u00f6schen via Path-Traversal), import (Template-Style-Settings \\u00fcberschreiben) sowie upload_image\\/remove_image\\/updateFonts. Legitime Gast-Aktionen (voting, load) und eingeloggte Template-Nutzung \",\"desc_en\":\"Helix3 < 3.1.1: the onAjaxHelix3 ajax handler checked neither login nor permission. Targets the dangerous unauth POST-body actions: save (write layout JSON into the active template), remove (delete a file via path traversal), import (overwrite template style settings) plus upload_image\\/remove_image\\/updateFonts. Legitimate guest actions (voting, load) and logged-in template use are unaffected. Fix:\",\"default\":1,\"qs\":\"data(?:\\\\[|%5b)action(?:\\\\]|%5d)=(?:save|remove|import|updatefonts)|action=(?:upload_image|remove_image)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"helix3-comajax\",\"label\":\"Helix3 (JoomShaper): unauth. com_ajax-Dispatcher (Datei-Write\\/Delete, Style-Injektion)\",\"label_en\":\"Helix3 (JoomShaper): unauth com_ajax dispatcher (file write\\/delete, style injection)\",\"desc\":\"Helix3 < 3.1.1: der Front-Dispatcher (option=com_ajax mit plugin=helix3) rief onAjaxHelix3 VOR jeder Token-\\/Rechtepr\\u00fcfung auf - unauthentifiziert save\\/import\\/remove\\/resetLayout\\/updateFonts\\/fontVariants (Datei-Schreiben, Path-Traversal-L\\u00f6schen, Template-Style-Injektion, Stored XSS). Blockt jeden GAST-Aufruf dieses Dispatchers im Frontend (Defense-in-Depth, f\\u00e4ngt auch laufende Scans) - erg\\u00e4nzt d\",\"desc_en\":\"Helix3 < 3.1.1: the front-end dispatcher (option=com_ajax with plugin=helix3) invoked onAjaxHelix3 BEFORE any token\\/permission check - unauthenticated save\\/import\\/remove\\/resetLayout\\/updateFonts\\/fontVariants (file write, path-traversal delete, template style injection, stored XSS). Blocks every GUEST call of this dispatcher on the front end (defense in depth, also catches ongoing scans) - complemen\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*plugin=helix3\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"helixultimate-comajax\",\"label\":\"Helix Ultimate (JoomShaper): unauth. com_ajax-Dispatcher (Men\\u00fc-Write\\/Datei\\/Export)\",\"label_en\":\"Helix Ultimate (JoomShaper): unauth com_ajax dispatcher (menu write\\/file\\/export)\",\"desc\":\"Helix Ultimate < 2.2.7: der com_ajax-Handler onAjaxHelixultimate (option=com_ajax mit plugin=helixultimate, Action im task-Param) lief VOR jeder Login-\\/Rechtepr\\u00fcfung - ein anonymer Angreifer konnte in die Men\\u00fc-Einstellungen schreiben (Stored XSS bis in die Admin-Sitzung), Dateien per Path-Traversal beliebig l\\u00f6schen, einen Open Redirect ausl\\u00f6sen und das Template ungesch\\u00fctzt exportieren. Blockt\",\"desc_en\":\"Helix Ultimate < 2.2.7: the com_ajax handler onAjaxHelixultimate (option=com_ajax with plugin=helixultimate, action in the task param) ran BEFORE any login\\/permission check - an anonymous attacker could write into the menu settings (stored XSS reaching the admin session), delete files anywhere via path traversal, trigger an open redirect and export the template unprotected. Blocks every GUEST call\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*plugin=helixultimate\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"comajax-include\",\"label\":\"com_ajax: Datei-Einbindung (generisch)\",\"label_en\":\"com_ajax: file inclusion (generic)\",\"desc\":\"F\\u00e4ngt unbekannte LFI-L\\u00fccken derselben Klasse ab: com_ajax mit task=include\\/require. Frontend.\",\"desc_en\":\"Catches unknown LFI holes of the same class: com_ajax with task=include\\/require. Frontend.\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*task=(include|require)(_once)?)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"sppagebuilder-uploadicon\",\"label\":\"SP Page Builder: unauthentifizierter Icon-Upload (RCE)\",\"label_en\":\"SP Page Builder: unauthenticated icon upload (RCE)\",\"desc\":\"Zero-Day in SP Page Builder bis 6.6.1: der asset-Controller (task=asset.uploadCustomIcon) hatte keinerlei Zugriffs-\\/Login-Pr\\u00fcfung - unauthentifizierter Datei-Upload nach \\/media\\/com_sppagebuilder\\/assets\\/iconfont\\/ - RCE. Nur Mini-WAF (G\\u00e4ste), da eingeloggte Builder den Endpunkt legitim nutzen.\",\"desc_en\":\"Zero-day in SP Page Builder up to 6.6.1: the asset controller (task=asset.uploadCustomIcon) had no access\\/login check - unauthenticated file upload to \\/media\\/com_sppagebuilder\\/assets\\/iconfont\\/ - RCE. Mini-WAF only (guests), since logged-in builders use the endpoint legitimately.\",\"default\":1,\"qs\":\"(?=.*option=com_sppagebuilder)(?=.*task=asset\\\\.uploadCustomIcon)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":null},{\"id\":\"dpcalendar-createdby-sqli\",\"label\":\"DPCalendar: unauth. SQL-Injection (Autor-Filter)\",\"label_en\":\"DPCalendar: unauth SQL injection (author filter)\",\"desc\":\"DPCalendar Blind-SQLi (Joomla 4.4-6 < 10.11.2, J3 < 8.19.4): der Frontend-Autor-Filter filter_created_by (option=com_dpcalendar, view=events) floss in skalarer Form ungecastet in a.created_by IN (...) - anonymes Auslesen beliebiger DB-Tabellen (nur lesend). Blockt Gast-Anfragen, deren filter_created_by kein reiner Integer ist (legitim = Autor-IDs\\/Ziffern) -> FP-frei. Fix 10.11.2 \\/ 8.19.4.\",\"desc_en\":\"DPCalendar blind SQLi (Joomla 4.4-6 < 10.11.2, J3 < 8.19.4): the front-end author filter filter_created_by (option=com_dpcalendar, view=events) flowed uncast into a.created_by IN (...) in its scalar form - anonymous read of arbitrary DB tables (read-only). Blocks guest requests whose filter_created_by is not a pure integer (legit = author IDs\\/digits) -> FP-free. Fix 10.11.2 \\/ 8.19.4.\",\"default\":1,\"qs\":\"(?=.*option=com_dpcalendar)(?=.*filter_created_by=[0-9,]*[^0-9,&])\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_dpcalendar\"},{\"id\":\"acym-entityselect-sqli\",\"label\":\"AcyMailing: unauth. SQL-Injection (Entity-Select Spaltenliste)\",\"label_en\":\"AcyMailing: unauth SQL injection (entity-select column list)\",\"desc\":\"CVE-2026-56292 (AcyMailing 6.0.0-10.11.0): der Frontend-Endpunkt EntitySelectController::loadEntityFront (option=com_acym, task=loadEntityFront) nahm die Request-Parameter columns\\/join_table ungeprueft in die SELECT-Spaltenliste von UserClass::getMatchingElements auf - ein anonymer Besucher konnte per Subquery beliebige DB-Tabellen (inkl. Passwort-Hashes) auslesen. Blockt GAST-Aufrufe dieses Tasks\",\"desc_en\":\"CVE-2026-56292 (AcyMailing 6.0.0-10.11.0): the front-end endpoint EntitySelectController::loadEntityFront (option=com_acym, task=loadEntityFront) placed the request parameters columns\\/join_table unchecked into the SELECT column list of UserClass::getMatchingElements - an anonymous visitor could read arbitrary DB tables (incl. password hashes) via a subquery. Blocks GUEST calls of this task whose c\",\"default\":1,\"qs\":\"(?=.*option=com_acym)(?=.*task=loadEntityFront)(?=.*(?:columns|join_table|join)=[^&]*(?:\\\\(|%28|%2528|\\\\s|%20|\\\\+))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_acym\"},{\"id\":\"quix-article-sqli\",\"label\":\"Quix Page Builder: unauth. SQL-Injection (Einzel-Artikel-AJAX)\",\"label_en\":\"Quix Page Builder: unauth SQL injection (single-article AJAX)\",\"desc\":\"Quix (ThemeXpert, Free UND Pro) bis 6.2.0, inkl. der 5.x-Reihe: der oeffentliche AJAX-Endpunkt (option=com_quix, task=ajax, element=joomla-article) ruft QuixJoomlaArticleElement::getAjax() ohne Login-\\/Token-\\/Lizenz-Pruefung; die Artikel-ID kommt base64-kodiert im data-Parameter und wird in articleExist() UNGECASTET in die DB-Query konkateniert -> unauthentifizierte, fehler-basierte SQL-Injection (\",\"desc_en\":\"Quix (ThemeXpert, Free AND Pro) up to 6.2.0, incl. the 5.x line: the public AJAX endpoint (option=com_quix, task=ajax, element=joomla-article) calls QuixJoomlaArticleElement::getAjax() with no login\\/token\\/license check; the article id arrives base64-encoded in the data parameter and is concatenated UNCAST into the DB query in articleExist() -> unauthenticated error-based SQL injection (CVSS 8.7). \",\"default\":1,\"qs\":\"(?=.*option=com_quix)(?=.*task=ajax\\\\b)(?=.*element=joomla-article\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_quix\"},{\"id\":\"joomcck-tags-sqli\",\"label\":\"JoomCCK: unauth. SQL-Injection (Tag-Verwaltung)\",\"label_en\":\"JoomCCK: unauth SQL injection (tag management)\",\"desc\":\"CVE-2026-49048 (JoomCCK 6.x vor 6.4.1): der Front-End-Task tags.save\\/tags.delete (option=com_joomcck) lief OHNE Token-\\/Login-\\/Rechte-Pruefung und schob den Request-Parameter tag (getString) roh - mit Double-Quote-Ausbruch - in ZWEI aufeinanderfolgende SQL-Statements (Existenz-SELECT + UPDATE). Ein anonymer Besucher konnte die Datenbank auslesen und veraendern (stacked\\/error-based SQLi). Blockt jed\",\"desc_en\":\"CVE-2026-49048 (JoomCCK 6.x before 6.4.1): the front-end task tags.save\\/tags.delete (option=com_joomcck) ran with NO token\\/login\\/permission check and concatenated the request parameter tag (getString) raw - with a double-quote breakout - into TWO consecutive SQL statements (existence SELECT + UPDATE). An anonymous visitor could read and modify the database (stacked\\/error-based SQLi). Blocks every \",\"default\":1,\"qs\":\"(?=.*option=com_joomcck)(?=.*task=tags\\\\.(?:save|delete))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_joomcck\"},{\"id\":\"gridbox-store-register\",\"label\":\"Balbooa Gridbox: unauth. Konto-Erstellung (store.register)\",\"label_en\":\"Balbooa Gridbox: unauth account creation (store.register)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, gemeldet 2026-07-28, Fix in 2.20.2 (29.07.2026). Der Front-End-Task store.register lief OHNE Login\\/Token und legte ein Joomla-Konto mit FREI WAEHLBARER Usergruppe plus sofort gueltiger Session an (unauth Privilege Escalation). Blockt jeden Gast-Aufruf dieses Tasks. Kosten: falls die Site die Gridbox-eigene Frontend-Registrierung nu\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to and incl. 2.20.1 - actively exploited, reported 2026-07-28, fixed in 2.20.2 (29 Jul 2026). The front-end task store.register ran WITHOUT login\\/token and created a Joomla account with an ARBITRARY usergroup plus an immediately valid session (unauth privilege escalation). Blocks every guest call of this task. Cost: if the site uses Gridbox front-end registration (\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=store(\\\\.|%2e)register)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":\"com_gridbox\"},{\"id\":\"gridbox-uploader-showimage-read\",\"label\":\"Balbooa Gridbox: unauth. Datei-Lesen (uploader.showImage)\",\"label_en\":\"Balbooa Gridbox: unauth arbitrary file read (uploader.showImage)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, Fix in 2.20.2 (29.07.2026). Der Front-End-Task uploader.showImage laed ohne Login den Query-Parameter image= und gibt bei Nicht-Bildern die Datei roh aus (fopen+fpassthru) -> unauth Arbitrary File Read, u. a. configuration.php. Trifft JEDE Gridbox-Installation. SURGICAL: greift NUR, wenn image= ein Angriffsmuster enthaelt (Pfad-Kle\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to and incl. 2.20.1 - actively exploited, fixed in 2.20.2 (29 Jul 2026). The front-end task uploader.showImage reads the query parameter image= without login and, for non-images, dumps the file raw (fopen+fpassthru) -> unauth arbitrary file read incl. configuration.php. Hits EVERY Gridbox install. SURGICAL: fires ONLY when image= contains an attack pattern (travers\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=uploader(\\\\.|%2e)showImage)(?=.*image=(?:%2f|\\/|[a-z]:|[a-z]%3a|[^&]*(?:\\\\.\\\\.|%2e%2e|\\\\.php|%2ephp|%00|php:|php%3a|:%2f%2f|:\\/\\/)))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":\"com_gridbox\"},{\"id\":\"gridbox-uploader-savephoto\",\"label\":\"Balbooa Gridbox: unauth. Datei-Schreiben (uploader.savePhotoEditorImage)\",\"label_en\":\"Balbooa Gridbox: unauth arbitrary file write (uploader.savePhotoEditorImage)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, Fix in 2.20.2 (29.07.2026). Der Front-End-Task uploader.savePhotoEditorImage schreibt eine beliebige Datei (inkl. .php) in den Webroot; der Zieldateiname liegt im POST-Body (php:\\/\\/input) und ist fuer die .htaccess unsichtbar, und eingeloggte Redakteure nutzen den Endpunkt legitim. Daher waf_only + scope=guest: NUR im Echtzeit-Plugi\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to and incl. 2.20.1 - actively exploited, fixed in 2.20.2 (29 Jul 2026). The front-end task uploader.savePhotoEditorImage writes an arbitrary file (incl. .php) into the webroot; the target filename is in the POST body (php:\\/\\/input), invisible to .htaccess, and logged-in editors use the endpoint legitimately. Hence waf_only + scope=guest: enforced ONLY in the real-t\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=uploader(\\\\.|%2e)savePhotoEditorImage)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_gridbox\"},{\"id\":\"baforms-signature-rce\",\"label\":\"Balbooa Forms: unauth. RCE (Signature-Feld, CVE-2026-65880)\",\"label_en\":\"Balbooa Forms: unauth RCE (signature field, CVE-2026-65880)\",\"desc\":\"Balbooa Forms (com_baforms) bis inkl. 2.4.2.1 - CVE-2026-65880 (CVSS 10.0), aktiv ausgenutzt, Fix erst 2.4.3. Beim Absenden eines Formulars mit SIGNATURE-Feld (task=form.sendMessage) verwendet FormModel::saveSignature den vom Angreifer im Feld-JSON gelieferten Funktionsnamen dynamisch als aufgerufene Funktion mit angeh\\u00e4ngtem Wert - unauthentifizierte Remote Code Execution. Der legitime Wert ist i\",\"desc_en\":\"Balbooa Forms (com_baforms) up to and incl. 2.4.2.1 - CVE-2026-65880 (CVSS 10.0), actively exploited, fixed only in 2.4.3. Submitting a form with a SIGNATURE field (task=form.sendMessage) makes FormModel::saveSignature use the attacker-supplied function name from the field JSON dynamically as the called function with an appended value - unauthenticated remote code execution. The legitimate value i\",\"default\":1,\"qs\":\"(?=.*\\\\bmethod[^a-z0-9]{1,6}(?:system|exec|shell_exec|passthru|assert|popen|proc_open|pcntl_exec|file_get_contents|readfile|show_source|highlight_file|fopen|scandir|phpinfo|eval|create_function|call_user_func)\\\\b)(?=.*\\\\bimage\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":1,\"trigger\":\"com_baforms\"},{\"id\":\"traversal-encoded\",\"label\":\"Pfad-Klettern (kodierte Varianten)\",\"label_en\":\"Path traversal (encoded variants)\",\"desc\":\"Erg\\u00e4nzt den Standard-Filter um Umgehungstricks: ....\\/\\/ , doppelte Kodierung (%252e), %c0%ae, %2e%2e%5c.\",\"desc_en\":\"Extends the standard filter with bypass tricks: ....\\/\\/ , double encoding (%252e), %c0%ae, %2e%2e%5c.\",\"default\":1,\"qs\":\"(\\\\.{3,}\\/|%252e|%c0%a[ef]|%2e%2e%5c|\\\\.\\\\.%5c)\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"php-wrapper-uri\",\"label\":\"PHP-Stream-Wrapper im Pfad\",\"label_en\":\"PHP stream wrapper in the path\",\"desc\":\"Blockiert php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ , expect:\\/\\/ u. a. direkt im angefragten Pfad.\",\"desc_en\":\"Blocks php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ , expect:\\/\\/ etc. directly in the requested path.\",\"default\":1,\"qs\":null,\"uri\":\"(?:php|phar|data|expect|glob|zlib|zip):\\/\",\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"api-config-leak\",\"label\":\"Joomla-API Konfigurations-Leak\",\"label_en\":\"Joomla API configuration leak\",\"desc\":\"CVE-2023-23752: sch\\u00fctzt den Endpunkt \\/api\\/...\\/v1\\/config\\/application auch ohne komplette API-Sperre.\",\"desc_en\":\"CVE-2023-23752: protects the \\/api\\/...\\/v1\\/config\\/application endpoint even without a complete API block.\",\"default\":1,\"qs\":null,\"uri\":\"^api\\/index\\\\.php\\/v[0-9]+\\/config\",\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"php-object-injection\",\"label\":\"PHP Object Injection (serialisierte Payload)\",\"label_en\":\"PHP object injection (serialised payload)\",\"desc\":\"Serialisiertes PHP-Objekt in einem Parameter (O:\\/C:<L\\u00e4nge>:) - typischer Einstieg f\\u00fcr Object-Injection\\/POP-Ketten. Kommt in normalen Anfragen nicht vor.\",\"desc_en\":\"Serialised PHP object in a parameter (O:\\/C:<length>:) - typical entry point for object injection\\/POP chains. Does not occur in normal requests.\",\"default\":1,\"qs\":\"(?<![a-z0-9])[oc]:[0-9]{1,4}:\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"stream-wrapper-param\",\"label\":\"PHP-Stream-Wrapper in Parameter\",\"label_en\":\"PHP stream wrapper in a parameter\",\"desc\":\"php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ u. a. als Parameterwert - LFI\\/RCE-Vektor. Erg\\u00e4nzt die Pfad-Variante (php-wrapper-uri).\",\"desc_en\":\"php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ etc. as a parameter value - LFI\\/RCE vector. Complements the path variant (php-wrapper-uri).\",\"default\":1,\"qs\":\"(php|phar|data|expect|glob|zlib|zip):\\/{2}\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"param-traversal\",\"label\":\"Pfad-Klettern im Parameter\",\"label_en\":\"Path traversal in a parameter\",\"desc\":\"Mehrfaches ..\\/ als Parameterwert - generisches Directory-Traversal\\/LFI in beliebigen Komponenten.\",\"desc_en\":\"Repeated ..\\/ as a parameter value - generic directory traversal\\/LFI in any component.\",\"default\":1,\"qs\":\"=(\\\\.\\\\.\\/){2,}\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null}],\"vuln_extensions\":[{\"element\":\"aimycaptchalessformguard\",\"type\":\"plugin\",\"folder\":\"captcha\",\"name\":\"Aimy Captcha-Less Form Guard\",\"below\":\"20.1\",\"above\":\"17.0\",\"severity\":\"high\",\"note\":\"Sicherheitsl\\u00fccke in 18.0 bis 20.0, vom Hersteller in 20.1 behoben (freie und PRO-Edition betroffen). Kein Workaround - auf Aimy Captcha-Less Form Guard 20.1 oder neuer aktualisieren.\",\"note_en\":\"Security issue in 18.0 to 20.0, fixed by the vendor in 20.1 (free and PRO edition affected). No workaround - update to Aimy Captcha-Less Form Guard 20.1 or newer.\",\"advisory\":\"https:\\/\\/www.aimy-extensions.com\\/joomla\\/captcha-less-form-guard.html\",\"advisory_en\":\"https:\\/\\/www.aimy-extensions.com\\/joomla\\/captcha-less-form-guard.html\"},{\"element\":\"com_easystore\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EasyStore (JoomShaper)\",\"below\":\"2.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere unauthentifizierte SQL-Injections (CVE-2026-65759 ff.). Auf EasyStore 2.0.2 oder neuer aktualisieren.\",\"note_en\":\"Multiple unauthenticated SQL injections (CVE-2026-65759 ff.). Update to EasyStore 2.0.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65759\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65759\"},{\"element\":\"com_splms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP LMS (JoomShaper)\",\"below\":\"4.1.4\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-48909: unauth. Code-Ausf\\u00fchrung durch unsichere Cookie-Deserialisierung. Auf SP LMS 4.1.4 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48909: unauthenticated code execution via insecure cookie deserialization. Update to SP LMS 4.1.4 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-48909\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-48909\"},{\"element\":\"com_osmembership\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Membership Pro (JoomDonation)\",\"below\":\"4.6.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-62415: kritische L\\u00fccke durch unsichere Standardkonfiguration. Auf Membership Pro 4.6.2 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-62415: critical flaw caused by an insecure default configuration. Update to Membership Pro 4.6.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-62415\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-62415\"},{\"element\":\"com_convertforms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Convert Forms (Tassos)\",\"below\":\"5.2.3\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische L\\u00fccken bis 5.2.2 (Datei-L\\u00f6schung, Datenleck; CVE-2024-40744). Auf Convert Forms 5.2.3 oder neuer aktualisieren.\",\"note_en\":\"Multiple critical flaws up to 5.2.2 (arbitrary file deletion, data exposure; CVE-2024-40744). Update to Convert Forms 5.2.3 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2024-40744\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2024-40744\"},{\"element\":\"sourcerer\",\"type\":\"plugin\",\"folder\":\"editors-xtd\",\"name\":\"Sourcerer (Regular Labs)\",\"below\":\"12.2.9\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2025-22204: Code-Injection durch mangelnde Rechtepr\\u00fcfung. Auf Sourcerer 12.2.9 oder neuer aktualisieren.\",\"note_en\":\"CVE-2025-22204: code injection due to missing permission checks. Update to Sourcerer 12.2.9 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-22204\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-22204\"},{\"element\":\"com_easydiscuss\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EasyDiscuss (StackIdeas)\",\"below\":\"5.0.16\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-21625: ACL-Umgehung im JSON-Output (Zugriff auf gesch\\u00fctzte Forendaten). Auf EasyDiscuss 5.0.16 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21625: access-control bypass in the JSON output exposing protected forum data. Update to EasyDiscuss 5.0.16 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-21625\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-21625\"},{\"element\":\"com_komento\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Komento (StackIdeas)\",\"below\":\"4.0.8\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2025-54294: SQL-Injection, ausnutzbar durch unprivilegierte Nutzer. Auf Komento 4.0.8 oder neuer aktualisieren.\",\"note_en\":\"CVE-2025-54294: SQL injection exploitable by unprivileged users. Update to Komento 4.0.8 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-54294\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-54294\"},{\"element\":\"nrframework\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Novarain \\/ Tassos Framework\",\"below\":\"6.0.38\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-21627: unauthentifizierte PHP-Einbindung via com_ajax. Auf 6.0.38 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21627: unauthenticated PHP inclusion via com_ajax. Update to 6.0.38 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/joomla-tassos-framework-novarain-framework-sicherheitsluecke\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/joomla-tassos-framework-novarain-framework-sicherheitsluecke\"},{\"element\":\"astroid\",\"type\":\"library\",\"folder\":\"\",\"name\":\"Astroid Framework\",\"below\":\"3.3.11\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-21628: unauthentifizierter Datei-Upload via AJAX-Endpunkt (Dropper in \\/images\\/). Auf 3.3.13 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21628: unauthenticated file upload via AJAX endpoint (dropper in \\/images\\/). Update to 3.3.13 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/joomla-astroid-framework-sicherheitsluecke-vulnerability\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/joomla-astroid-framework-sicherheitsluecke-vulnerability\"},{\"element\":\"helix3\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Helix3 (JoomShaper)\",\"below\":\"3.1.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Unauthentifizierter com_ajax-Handler (onAjaxHelix3) ohne Login-\\/Rechtepr\\u00fcfung: Angreifer k\\u00f6nnen Dateien ins aktive Template schreiben oder per Path-Traversal l\\u00f6schen (save\\/remove\\/import). Auf Helix3 3.1.1 oder neuer aktualisieren.\",\"note_en\":\"Unauthenticated com_ajax handler (onAjaxHelix3) with no login or permission check: attackers can write files into the active template or delete files via path traversal (save\\/remove\\/import). Update to Helix3 3.1.1 or newer.\",\"advisory\":\"https:\\/\\/htprotect.org\\/helix3\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/helix3\"},{\"element\":\"helixultimate\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Helix Ultimate (JoomShaper)\",\"below\":\"2.2.7\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Kritische unauth. L\\u00fccke in ALLEN Versionen < 2.2.7: der com_ajax-Handler onAjaxHelixultimate lief VOR jeder Rechtepr\\u00fcfung - anonym in die Men\\u00fcs schreiben (Stored XSS in den Admin), Path-Traversal-L\\u00f6schen, Open Redirect, Template-Export. Auf 2.2.7 updaten (Plugin UND Template). HTProtects Mini-WAF blockt den Aufruf bereits. NICHT mit Helix3 verwechseln.\",\"note_en\":\"Critical unauth flaw in ALL versions below 2.2.7: the com_ajax handler onAjaxHelixultimate ran before any permission check - anonymous menu writes (stored XSS reaching the admin), path-traversal delete, open redirect, template export. Update to 2.2.7 (plugin AND template). HTProtect mini-WAF already blocks the call. Not to be confused with Helix3.\",\"advisory\":\"https:\\/\\/htprotect.org\\/helix-ultimate\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/helix-ultimate\"},{\"element\":\"com_baforms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Balbooa Forms\",\"below\":\"2.4.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Aktiver Zero-Day (RCE), ALLE Versionen bis 2.4.0: der Upload-Endpoint form.uploadAttachmentFile pr\\u00fcft weder Login\\/Token noch Dateityp - ein anonymer Angreifer kann eine PHP-Datei hochladen und ausf\\u00fchren. NOCH KEIN Patch. Sofortma\\u00dfnahme: Upload-Formulare depublizieren. HTProtects Gast-Upload-Schutz blockt den ausf\\u00fchrbaren Upload bereits.\",\"note_en\":\"Active zero-day (RCE), ALL versions up to 2.4.0: the upload endpoint form.uploadAttachmentFile checks neither login\\/token nor file type - an anonymous attacker can upload and run a PHP file. NO patch yet. Interim: unpublish forms with upload fields. The HTProtect guest-upload filter already blocks the executable upload.\",\"advisory\":\"https:\\/\\/htprotect.org\\/balbooa-forms\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/balbooa-forms\"},{\"element\":\"com_jce\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JCE Editor\",\"below\":\"2.9.99.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-48907: unauthentifizierter Webshell-Upload (profiles.import + plugin.rpc). Dringend auf JCE 2.9.99.6 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48907: unauthenticated webshell upload (profiles.import + plugin.rpc). Urgently update to JCE 2.9.99.6 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/jce-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/jce-sicherheitsluecke-joomla\"},{\"element\":\"com_rsfiles\",\"type\":\"component\",\"folder\":\"\",\"name\":\"RSFiles!\",\"below\":\"1.17.12\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Aktiver unauthentifizierter Datei-Upload -> RCE, ALLE Versionen bis 1.17.11: der Frontend-Upload (task=rsfiles.upload) pr\\u00fcft weder Login\\/Token noch Dateiendung - ein anonymer Angreifer l\\u00e4dt eine .php nach \\/downloads bzw. \\/briefcase und f\\u00fchrt sie aus. Dringend auf 1.17.12 aktualisieren. HTProtects Gast-Upload-Schutz blockt den ausf\\u00fchrbaren Upload bereits.\",\"note_en\":\"Active unauthenticated file upload -> RCE, ALL versions up to 1.17.11: the front-end upload (task=rsfiles.upload) checks neither login\\/token nor file extension - an anonymous attacker uploads a .php into \\/downloads or \\/briefcase and executes it. Update to 1.17.12 urgently. The HTProtect guest-upload filter already blocks the executable upload.\",\"advisory\":\"https:\\/\\/www.rsjoomla.com\\/blog\\/view\\/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html\",\"advisory_en\":\"https:\\/\\/www.rsjoomla.com\\/blog\\/view\\/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html\"},{\"element\":\"com_edocman\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EDocman\",\"below\":\"3.9\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Unauthentifizierte SQL-Injection (alle Versionen bis 3.8): ein anonymer Besucher schleust ueber einen Filter-Parameter eines oeffentlichen Frontend-Endpunkts SQL in eine ungequotete DB-Abfrage ein und kann die Datenbank auslesen (bis hin zu Zugangsdaten). Der genaue Vektor ist bewusst nicht veroeffentlicht. Dringend auf EDocman 3.9.0 aktualisieren.\",\"note_en\":\"Unauthenticated SQL injection (all versions up to 3.8): an anonymous visitor injects SQL through a filter parameter of a public front-end endpoint into an unquoted DB query and can read the database (up to credentials). The exact vector is deliberately undisclosed. Update to EDocman 3.9.0 urgently.\",\"advisory\":\"https:\\/\\/joomdonation.com\\/forum\\/edocman\\/82813-edocman-3-9-0-security-release---important-update-recommended.html\",\"advisory_en\":\"https:\\/\\/joomdonation.com\\/forum\\/edocman\\/82813-edocman-3-9-0-security-release---important-update-recommended.html\"},{\"element\":\"com_foranalytics\",\"type\":\"component\",\"folder\":\"\",\"name\":\"4Analytics\",\"below\":\"5.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Zwei unauthentifizierte Sicherheitsluecken (CVE-2026-57833 + CVE-2026-58077) in ALLEN Versionen vor 5.0.2 - ein anonymer Angreifer braucht keinen Login. Hersteller Weeblr stuft beide als kritisch ein; technische Details sind 7 Tage embargoed. Dringend auf 4Analytics 5.0.2 aktualisieren (laeuft auf Joomla 3-6).\",\"note_en\":\"Two unauthenticated security flaws (CVE-2026-57833 + CVE-2026-58077) in ALL versions before 5.0.2 - an anonymous attacker needs no login. Vendor Weeblr rates both critical; technical details are under a 7-day embargo. Update to 4Analytics 5.0.2 urgently (runs on Joomla 3-6).\",\"advisory\":\"https:\\/\\/weeblr.com\\/blog\\/critical-vulnerabilities-2026-07-15\",\"advisory_en\":\"https:\\/\\/weeblr.com\\/blog\\/critical-vulnerabilities-2026-07-15\"},{\"element\":\"com_quix\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Quix\",\"below\":\"6.2.1\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Unauthentifizierte SQL-Injection (Free UND Pro, alle Versionen vor 6.2.1 \\u2013 auch die 5.x-Reihe): ein anonymer Besucher kann die gesamte Datenbank auslesen (CVSS 8.7). HTProtects Mini-WAF blockt den Angriff bereits aktiv. Auf Quix 6.2.1 aktualisieren (Free erh\\u00e4lt 6.2.1 ebenfalls \\u00fcber die Update-Funktion).\",\"note_en\":\"Unauthenticated SQL injection (Free AND Pro, all versions below 6.2.1 \\u2013 including the 5.x line): an anonymous visitor can read the entire database (CVSS 8.7). HTProtect\'s mini-WAF already actively blocks the attack. Update to Quix 6.2.1 (Free receives 6.2.1 too via the update function).\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/quix-sql-injection-disclosure\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/quix-sql-injection-disclosure\\/\"},{\"element\":\"com_joomcck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JoomCCK\",\"below\":\"6.4.1\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"Unauthentifizierte SQL-Injection (CVE-2026-49048, JoomCCK 6.x vor 6.4.1): der Front-End-Task \\u201eTag speichern\\/l\\u00f6schen\\\" pr\\u00fcfte weder Login noch Token und \\u00fcbernahm den Parameter \\u201etag\\\" ungefiltert in zwei SQL-Abfragen - ein anonymer Besucher konnte die Datenbank auslesen und ver\\u00e4ndern. HTProtects Mini-WAF blockt den unautorisierten Gast-Aufruf bereits aktiv. Dringend auf JoomCCK 6.4.1 aktualisi\",\"note_en\":\"Unauthenticated SQL injection (CVE-2026-49048, JoomCCK 6.x before 6.4.1): the front-end \\\"save\\/delete tag\\\" task checked neither login nor token and took the \\\"tag\\\" parameter unfiltered into two SQL queries - an anonymous visitor could read and modify the database. HTProtect\'s mini-WAF already actively blocks the unauthorized guest call. Update to JoomCCK 6.4.1 urgently.\",\"advisory\":\"https:\\/\\/github.com\\/JoomCoder-com\\/JoomCCK\\/releases#release-6.4.1\",\"advisory_en\":\"https:\\/\\/github.com\\/JoomCoder-com\\/JoomCCK\\/releases#release-6.4.1\"},{\"element\":\"com_chronoforms8\",\"type\":\"component\",\"folder\":\"\",\"name\":\"ChronoForms\",\"below\":\"8.0.53\",\"above\":\"8.0.0\",\"severity\":\"high\",\"note\":\"Unauthentifizierte gespeicherte XSS (CVE-2026-58148, ChronoForms 8.x vor 8.0.53): ein anonymer Besucher schleust \\u00fcber ein Formular-Feld JavaScript ein, das ungefiltert gespeichert und sp\\u00e4ter - z. B. beim Ansehen der Einsendungen im Backend - ausgef\\u00fchrt wird, bis hin zur \\u00dcbernahme der Admin-Sitzung (CVSS 8.7). Auf ChronoForms 8.0.53 aktualisieren.\",\"note_en\":\"Unauthenticated stored XSS (CVE-2026-58148, ChronoForms 8.x before 8.0.53): an anonymous visitor injects JavaScript via a form field that is stored unfiltered and later executed - e.g. when viewing the submissions in the backend - up to takeover of the admin session (CVSS 8.7). Update to ChronoForms 8.0.53.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-58148\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-58148\"},{\"element\":\"com_jdownloads\",\"type\":\"component\",\"folder\":\"\",\"name\":\"jDownloads\",\"below\":\"4.1.6\",\"above\":\"4.1.0\",\"severity\":\"high\",\"note\":\"Unauthentifizierte Datei-Upload-L\\u00fccke (jDownloads 4.1.0-4.1.5): eine verwaiste Uploader-Datei (upload-handler.php) pr\\u00fcft weder Login noch Token und l\\u00e4sst einen anonymen Besucher beliebige Dateien - u. a. exe\\/msi\\/Archive - in einen Ordner der Site schreiben; auf manchen Servern bis zur Codeausf\\u00fchrung, sonst Malware-Hosting\\/Speicher-Flutung. HTProtects .htaccess-Schutzschild blockt den direkten \",\"note_en\":\"Unauthenticated file upload flaw (jDownloads 4.1.0-4.1.5): a leftover uploader file (upload-handler.php) checks neither login nor token and lets an anonymous visitor write arbitrary files - incl. exe\\/msi\\/archives - into a folder on the site; up to remote code execution on some servers, otherwise malware hosting \\/ disk flooding. HTProtect\'s .htaccess shield already blocks direct access to the file \",\"advisory\":\"https:\\/\\/www.jdownloads.com\\/index.php\\/news\\/jdownloads-4-1-6-secure-update-released.html\",\"advisory_en\":\"https:\\/\\/www.jdownloads.com\\/index.php\\/news\\/jdownloads-4-1-6-secure-update-released.html\"},{\"element\":\"com_dpcalendar\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DPCalendar\",\"below\":\"10.11.2\",\"above\":\"9.0.0\",\"severity\":\"high\",\"note\":\"DPCalendar (Joomla 4.4-6, 9.0.0-10.11.1): unauthentifizierte Blind-SQL-Injection - der Autor-Filter filter_created_by (Frontend view=events) floss in skalarer Form ohne Integer-Cast in die Query (a.created_by IN ...); ein anonymer Besucher kann beliebige DB-Tabellen AUSLESEN (nichts \\u00e4ndern). Dringend auf 10.11.2 aktualisieren. HTProtects Mini-WAF blockt die Injektion bereits.\",\"note_en\":\"DPCalendar (Joomla 4.4-6, 9.0.0-10.11.1): unauthenticated blind SQL injection - the author filter filter_created_by (front-end view=events) flowed uncast (scalar form) into the query (a.created_by IN ...); an anonymous visitor can READ arbitrary DB tables (no writes). Update to 10.11.2 urgently. HTProtect mini-WAF already blocks the injection.\",\"advisory\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\",\"advisory_en\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\"},{\"element\":\"com_dpcalendar\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DPCalendar\",\"below\":\"8.19.4\",\"above\":\"8.18.0\",\"severity\":\"high\",\"note\":\"DPCalendar Joomla-3-Linie (8.x), 8.18.0-8.19.3: dieselbe unauth Blind-SQL-Injection \\u00fcber den Autor-Filter filter_created_by (skalar, ohne Integer-Cast, nur lesend). In 8.19.4 (Joomla-3-Fix) behoben. Auf 8.19.4 aktualisieren. HTProtects Mini-WAF blockt die Injektion bereits.\",\"note_en\":\"DPCalendar Joomla 3 line (8.x), 8.18.0-8.19.3: same unauth blind SQL injection via the author filter filter_created_by (scalar, no integer cast, read-only). Fixed in 8.19.4 (Joomla 3 fix). Update to 8.19.4. HTProtect mini-WAF already blocks the injection.\",\"advisory\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\",\"advisory_en\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\"},{\"element\":\"com_phocadownload\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Download\",\"below\":\"6.1.3\",\"above\":\"6.0.0\",\"severity\":\"high\",\"note\":\"Authentifizierter Datei-Upload -> RCE (Versionen 6.0 bis 6.1.2): ein eingeloggter Nutzer mit Zugriff auf die Upload-Funktion kann eine ausf\\u00fchrbare Datei (z. B. .php) hochladen und ausf\\u00fchren. In 6.1.3 (Security-Release) behoben - auf 6.1.3 oder neuer aktualisieren. HTProtects PHP-Schild verhindert die Ausf\\u00fchrung einer hochgeladenen PHP-Datei in den Upload-Ordnern bereits.\",\"note_en\":\"Authenticated file upload -> RCE (versions 6.0 to 6.1.2): a logged-in user with access to the upload feature can upload and run an executable file (e.g. .php). Fixed in 6.1.3 (security release) - update to 6.1.3 or newer. The HTProtect PHP shield already prevents execution of an uploaded PHP file in the upload folders.\",\"advisory\":\"https:\\/\\/www.phoca.cz\\/news\\/1481-phoca-download-version-6-1-3-released-security-release\",\"advisory_en\":\"https:\\/\\/www.phoca.cz\\/news\\/1481-phoca-download-version-6-1-3-released-security-release\"},{\"element\":\"com_phocamaps\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Maps\",\"below\":\"6.1.0\",\"above\":\"5.0.0\",\"severity\":\"medium\",\"note\":\"CVE-2026-65763: reflektiertes XSS (5.0.0-6.0.4) durch unzureichende Eingabepr\\u00fcfung - ein Angreifer bringt einen Besucher \\u00fcber einen pr\\u00e4parierten Link dazu, eingeschleustes JavaScript auszuf\\u00fchren. Auf Phoca Maps 6.1.0 (Security-Release) oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-65763: reflected XSS (5.0.0-6.0.4) via improper input validation - an attacker lures a visitor with a crafted link to run injected JavaScript. Update to Phoca Maps 6.1.0 (security release) or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65763\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65763\"},{\"element\":\"com_phocaguestbook\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Guestbook\",\"below\":\"6.1.1\",\"above\":\"5.0.0\",\"severity\":\"medium\",\"note\":\"CVE-2026-65762: reflektiertes XSS (5.0.0-6.1.0) durch unzureichende Eingabepr\\u00fcfung - ein pr\\u00e4parierter Link f\\u00fchrt beim Besucher eingeschleustes JavaScript aus. Auf Phoca Guestbook 6.1.1 (Security-Release) oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-65762: reflected XSS (5.0.0-6.1.0) via improper input validation - a crafted link runs injected JavaScript in the visitor\'s browser. Update to Phoca Guestbook 6.1.1 (security release) or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65762\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65762\"},{\"element\":\"com_acym\",\"type\":\"component\",\"folder\":\"\",\"name\":\"AcyMailing 6+\",\"below\":\"10.11.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"AcyMailing Neuauflage (6+): CVE-2026-56292 unauthentifizierte SQL-Injection (6.0.0-10.11.0) - ein anonymer Angreifer liest beliebige DB-Tabellen inkl. Passwort-Hashes (CVSS 8.7). \\u00c4ltere L\\u00fccken: CVE-2023-28731 unauth Upload\\/RCE unter 8.3.0, CVE-2026-3614 Rechteausweitung 9.11.0-10.8.1. Dringend auf 10.11.1 aktualisieren.\",\"note_en\":\"AcyMailing new line (6+): CVE-2026-56292 unauthenticated SQL injection (6.0.0-10.11.0) - an anonymous attacker reads arbitrary DB tables incl. password hashes (CVSS 8.7). Older holes: CVE-2023-28731 unauth upload\\/RCE below 8.3.0, CVE-2026-3614 privilege escalation 9.11.0-10.8.1. Update to 10.11.1 urgently.\",\"advisory\":\"https:\\/\\/htprotect.org\\/acymailing\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/acymailing\"},{\"element\":\"com_acymailing\",\"type\":\"component\",\"folder\":\"\",\"name\":\"AcyMailing Classic\",\"below\":\"4.9.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"AcyMailing Classic (End-of-Life): \\u00e4ltere Versionen mit kritischen L\\u00fccken - unauthentifizierter Datei-Upload der 3.x-\\u00c4ra (RCE, z. B. 3.9.0) sowie Backend-SQL-Injection CVE-2015-7338 (in 4.9.5 behoben). Auf eine unterst\\u00fctzte AcyMailing-Version migrieren. (Die 5.x-Linie hat keine bekannte sehr kritische L\\u00fccke; CSV-Injection CVE-2018-9107 in 5.9.1-5.9.5 ist niedrig\\/client-seitig.)\",\"note_en\":\"AcyMailing Classic (end-of-life): older versions with critical holes - unauthenticated file upload of the 3.x era (RCE, e.g. 3.9.0) and backend SQL injection CVE-2015-7338 (fixed in 4.9.5). Migrate to a supported AcyMailing version. (The 5.x line has no known very critical hole; CSV injection CVE-2018-9107 in 5.9.1-5.9.5 is low\\/client-side.)\",\"advisory\":\"https:\\/\\/htprotect.org\\/acymailing\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/acymailing\"},{\"element\":\"com_igallery\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Ignite Gallery\",\"below\":\"5.4.1\",\"above\":\"5.0.0\",\"severity\":\"high\",\"note\":\"Ignite Gallery 5.0.0 bis 5.4.0: Stored XSS (hoch) durch fehlendes Output-Escaping beim Hochladen\\/Bearbeiten von Bildern, dazu SSRF (ungefilterte Video-URL) und eine Rechteausweitung beim Download geschuetzter\\/unveroeffentlichter Bilder. Ausnutzbar von Nutzern MIT Upload-\\/Bearbeitungsrecht (Frontend oder Backend). Auf 5.4.1 oder neuer aktualisieren.\",\"note_en\":\"Ignite Gallery 5.0.0 to 5.4.0: stored XSS (high) via missing output escaping when uploading\\/editing images, plus SSRF (unfiltered video URL) and a privilege escalation when downloading restricted\\/unpublished images. Exploitable by users WITH upload\\/edit permission (frontend or backend). Update to 5.4.1 or newer.\",\"advisory\":\"https:\\/\\/www.ignitegallery.com\\/documentation\\/changelog\",\"advisory_en\":\"https:\\/\\/www.ignitegallery.com\\/documentation\\/changelog\"},{\"element\":\"com_icagenda\",\"type\":\"component\",\"folder\":\"\",\"name\":\"iCagenda\",\"below\":\"4.0.8\",\"above\":\"4.0.0\",\"severity\":\"critical\",\"note\":\"CVE-2026-48939 (4.x-Linie 4.0.0-4.0.7): das Event-Formular (task=submit.submit) pr\\u00fcft nur das CSRF-Token, keine Zugriffsrechte - anonymer Datei-Upload. Voller RCE nur auf Joomla 6 (Core blockt .php nicht mehr); auf Joomla <=5 mildert der Core-Filter, die Zugriffsl\\u00fccke bleibt. Dringend auf 4.0.8 aktualisieren. HTProtects Dateischild verhindert die Ausf\\u00fchrung bereits.\",\"note_en\":\"CVE-2026-48939 (4.x line 4.0.0-4.0.7): the event form (task=submit.submit) checks only the CSRF token, no access rights - anonymous file upload. Full RCE only on Joomla 6 (core no longer blocks .php); on Joomla <=5 the core filter mitigates but the access flaw remains. Update to 4.0.8 urgently. The HTProtect file shield already prevents execution.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/icagenda-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/icagenda-sicherheitsluecke-joomla\"},{\"element\":\"com_icagenda\",\"type\":\"component\",\"folder\":\"\",\"name\":\"iCagenda\",\"below\":\"3.9.15\",\"above\":\"3.2.1\",\"severity\":\"critical\",\"note\":\"CVE-2026-48939, 3.x-Linie 3.2.1-3.9.14: dieselbe Zugriffsl\\u00fccke im Event-Formular (task=submit.submit, keine Rechtepr\\u00fcfung, anonymer Datei-Upload). In 3.9.15 (Security-Backport f\\u00fcr Joomla 3) behoben. Dringend auf 3.9.15 aktualisieren. HTProtects Dateischild verhindert die Ausf\\u00fchrung bereits. (Voller RCE v. a. auf Joomla 6.)\",\"note_en\":\"CVE-2026-48939, 3.x line 3.2.1-3.9.14: same access-control flaw in the event form (task=submit.submit, no permission check, anonymous file upload). Fixed in 3.9.15 (security backport for Joomla 3). Update to 3.9.15 urgently. The HTProtect file shield already prevents execution. (Full RCE mainly on Joomla 6.)\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/icagenda-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/icagenda-sicherheitsluecke-joomla\"},{\"element\":\"com_sppagebuilder\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP Page Builder\",\"below\":\"6.7.1\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"Unauthentifizierte SQL-Injection (CVE-2026-65766) bis Version 6.7.0: ein anonymer Besucher liest \\u00fcber einen ungefilterten Parameter (direction) im Dynamic-Content-Endpunkt beliebige Datenbank-Tabellen aus - bis zu Benutzerkonten, Passwort-Hashes und dem Seiten-Geheimnis (CVSS 8.7). Dazu ein offenes Mail-Relay (CVE-2026-65877): Angreifer verschicken \\u00fcber die Kontaktformular-Addons beliebige E-Mai\",\"note_en\":\"Unauthenticated SQL injection (CVE-2026-65766) up to version 6.7.0: via an unfiltered parameter (direction) in the Dynamic Content endpoint an anonymous visitor can read arbitrary database tables - down to user accounts, password hashes and the site secret (CVSS 8.7). Plus an open mail relay (CVE-2026-65877): attackers send arbitrary emails with a spoofed sender through the contact-form addons. Up\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/sp-page-builder-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/sp-page-builder-sicherheitsluecke-joomla\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.6\",\"above\":\"3.5.0\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) bis 3.5.10: ein Front-End-Upload-Endpunkt (zum Hinzuf\\u00fcgen von Bildern) pr\\u00fcfte nur das CSRF-Token, aber keine Zugriffsrechte und keinen Dateityp - ein nicht eingeloggter Angreifer konnte eine beliebige Datei (z. B. PHP-Shell) in einen frei w\\u00e4hlbaren Ordner hochladen und ausf\\u00fchren (Remote Code Execution). Dringend auf 3.6.0 aktualisieren. (HTProtects generischer Upload-Sch\",\"note_en\":\"Critical flaw (RCE) up to 3.5.10: a front-end upload endpoint (for adding images) only verified the CSRF token but no access rights and no file type - an unauthenticated attacker could upload an arbitrary file (e.g. a PHP shell) into a freely chosen folder and execute it (remote code execution). Update to 3.6.0 urgently. (The HTProtect generic upload protection already blocks the unauthenticated u\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.4.10\",\"above\":\"3.2.0\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) in der Joomla-4-Linie unter 3.4.10: unauthentifizierter Datei-Upload \\u00fcber einen Front-End-Endpunkt (nur CSRF-Token, keine Zugriffs-\\/Typpr\\u00fcfung) - beliebige Datei in frei w\\u00e4hlbaren Ordner hochladbar und ausf\\u00fchrbar. In 3.4.10 (Backport) behoben. Dringend aktualisieren. (HTProtects generischer Upload-Schutz blockt den unauthentifizierten Upload bereits; das Dateischild verh\",\"note_en\":\"Critical flaw (RCE) in the Joomla 4 line below 3.4.10: unauthenticated file upload via a front-end endpoint (CSRF token only, no access\\/type check) - arbitrary file uploadable into a freely chosen folder and executable. Fixed in 3.4.10 (backport). Update urgently. (The HTProtect generic upload protection already blocks the unauthenticated upload; the file shield additionally prevents execution.)\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.1.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) in der Joomla-3-Linie unter 3.1.1: unauthentifizierter Datei-Upload \\u00fcber einen Front-End-Endpunkt (nur CSRF-Token, keine Zugriffs-\\/Typpr\\u00fcfung) - beliebige Datei in frei w\\u00e4hlbaren Ordner hochladbar und ausf\\u00fchrbar. In 3.1.1 (Backport f\\u00fcr Joomla 3) behoben. Dringend aktualisieren. (HTProtects generischer Upload-Schutz blockt den unauthentifizierten Upload bereits; das Date\",\"note_en\":\"Critical flaw (RCE) in the Joomla 3 line below 3.1.1: unauthenticated file upload via a front-end endpoint (CSRF token only, no access\\/type check) - arbitrary file uploadable into a freely chosen folder and executable. Fixed in 3.1.1 (backport for Joomla 3). Update urgently. (The HTProtect generic upload protection already blocks the unauthenticated upload; the file shield additionally prevents ex\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_eventbooking\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Events Booking\",\"below\":\"5.8.1\",\"above\":\"5.0\",\"severity\":\"medium\",\"note\":\"Zwei Sicherheitsl\\u00fccken ohne Anmeldung in allen Versionen der 5er-Reihe vor 5.8.1: Erstens konnte jeder anonyme Besucher \\u00fcber die Datei-Upload-Funktion des Anmeldeformulars Dateien auf dem Server ablegen - ohne Konto, ohne Anmeldung und ohne Sicherheitstoken; die Funktion war ab Werk in jeder Installation aktiv. Die abgelegten Dateien lie\\u00dfen sich anschlie\\u00dfend unter einem vorhersehbaren Namen wi\",\"note_en\":\"Two unauthenticated security flaws in all versions of the 5.x line below 5.8.1: First, any anonymous visitor could place files on the server through the file upload of the registration form - no account, no login, no security token; the feature was enabled by default in every installation. The uploaded files could then be retrieved again under a predictable name. Program files were not allowed in \",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/events-booking-unauthenticated-upload-user-enumeration\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/events-booking-unauthenticated-upload-user-enumeration\\/\"},{\"element\":\"com_djclassifieds\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DJ-Classifieds\",\"below\":\"3.11.2\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Schwerwiegende L\\u00fccke in allen Versionen bis einschlie\\u00dflich 3.11.1: Die Funktion zum Hochladen von Anzeigenbildern nahm Dateien entgegen, ohne dass eine Anmeldung n\\u00f6tig war und ohne die \\u00fcblichen Sicherheitspr\\u00fcfungen. Angreifer konnten dadurch eine Schaddatei auf der Website ablegen und im ung\\u00fcnstigen Fall die Kontrolle \\u00fcber die gesamte Seite \\u00fcbernehmen. Die L\\u00fccke wurde bereits aktiv ausgen\",\"note_en\":\"Serious flaw in all versions up to and including 3.11.1: the image upload used for classified ads accepted files without requiring a login and without the usual security checks. This allowed attackers to place a malicious file on the website and, in the worst case, take control of the entire site. The flaw was already being actively exploited before a fix was available. Update to version 3.11.2 or\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/dj-classifieds-unauthenticated-file-upload\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/dj-classifieds-unauthenticated-file-upload\\/\"},{\"element\":\"com_gridbox\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Gridbox\",\"below\":\"2.20.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Balbooa hat in zwei Schritten reagiert: 2.20.1 (20.07.2026) schloss eine kritische Anmelde-L\\u00fccke (CVE-2026-61425), blieb aber unvollst\\u00e4ndig. Erst 2.20.2 (29.07.2026) behebt - laut Hersteller in allen Versionen bis einschlie\\u00dflich 2.20.1 - unbefugten Dateizugriff (Lesen und Schreiben), das rekursive L\\u00f6schen ganzer Ordner, mehrere SQL-Einschleusungen, weitere Umgehungen der Rechtepr\\u00fcfung und Inf\",\"note_en\":\"Balbooa responded in two steps: 2.20.1 (20 Jul 2026) closed a critical authentication flaw (CVE-2026-61425) but was incomplete. Only 2.20.2 (29 Jul 2026) fixes - across all versions up to and including 2.20.1, per the vendor - unauthorized file access (read and write), recursive deletion of whole directories, multiple SQL injections, further authorization-check bypasses and information disclosure.\",\"advisory\":\"https:\\/\\/www.balbooa.com\\/blog\\/gridbox\\/gridbox-2-20-2-security-release\",\"advisory_en\":\"https:\\/\\/www.balbooa.com\\/blog\\/gridbox\\/gridbox-2-20-2-security-release\"}],\"php_min\":\"8.1\",\"fetched\":\"2026-08-01 01:42:25\",\"fetched_ts\":1785615665,\"etag\":\"\\\"6a6d343c-f907\\\"\",\"modified\":\"Fri, 31 Jul 2026 23:48:12 GMT\",\"joomla_latest\":{\"3\":\"3.10.12\",\"4\":\"4.4.14\",\"5\":\"5.4.7\",\"6\":\"6.1.2\"},\"joomla_latest_ts\":1785590511,\"joomla_latest_try\":1785590511},\"htp_malware\":{\"schema\":1,\"version\":\"2026-07-29.671bb5\",\"sigs\":[{\"id\":\"backdoor-prepend-sshkey\",\"all\":[\"auto_prepend_file\",\"authorized_keys\"]},{\"id\":\"cred-stealer-ctfaudit\",\"any\":[\"x-ctf-audit\",\"jlib_audit_gid\"]},{\"id\":\"upload-shell-form\",\"all\":[\"move_uploaded_file\",\"check directory permissions\"]},{\"id\":\"sppb-iconfont-shell\",\"any\":[\"sppbwhoami\"]},{\"id\":\"remote-eval-loader\",\"all\":[\"eval(\\\"?>\\\"\"],\"any\":[\"fetchcontentfromurl\",\"file_get_contents(\\\"http\",\"file_get_contents(\'http\"]},{\"id\":\"seo-doorway-slot\",\"any\":[\"slot gacor\",\"situs slot gacor\"]},{\"id\":\"filemanager-backdoor-data\",\"all\":[\"<?php exit;?>{\",\"\\\"groupinfo\\\"\",\"\\\"sizemax\\\"\"]},{\"id\":\"encrypted-eval-openssl\",\"all\":[\"openssl_raw_data\",\"aes-256-cbc\"],\"not\":[\"openssl_decrypt\",\"openssl_encrypt\"]},{\"id\":\"0xnix-split-encrypted\",\"all\":[\"0xnix encrypted code\"]},{\"id\":\"upload-shell-devco1\",\"all\":[\"move_uploaded_file\",\"devco1\"]},{\"id\":\"upload-shell-uname-form\",\"all\":[\"move_uploaded_file\",\"php_uname\",\"multipart\\/form-data\"]},{\"id\":\"hacktool-adminer\",\"all\":[\"adminer_errors\",\"idf_unescape\"]},{\"id\":\"webshell-range-obfuscator\",\"all\":[\"\\\"r\\\".\\\"a\\\".\\\"n\\\".\\\"g\\\".\\\"e\\\"\",\"eval\"]},{\"id\":\"webshell-md5quad-gate\",\"all\":[\"md5(md5(md5(md5(\",\"eval\"]},{\"id\":\"remote-loader-stream-include\",\"any\":[\"include stream_get_meta_data\",\"require stream_get_meta_data\",\"include(stream_get_meta_data\",\"require(stream_get_meta_data\"]},{\"id\":\"webshell-dual-uploader\",\"all\":[\"remote_url\",\"name=\\\"_upl\\\"\",\"name=\\\"_remote\\\"\"]},{\"id\":\"webshell-comment-obfuscator\",\"all\":[\"-*\\/\\/\\/\",\"\\\"~\\\"\"]},{\"id\":\"eval-openssl-shell\",\"label\":\"eval(openssl_decrypt) webshell\",\"all\":[\"eval(openssl_decrypt(\"]},{\"id\":\"dropper-drivergenius-c2\",\"label\":\"Remote-fetch dropper (drivergenius C2)\",\"all\":[\"drivergenius.it.com\"]},{\"id\":\"dropper-backdate-disguise\",\"label\":\"Remote-fetch dropper (mtime-forge + disguise)\",\"all\":[\"getreferencefiletime\",\"generatefilename\"]},{\"id\":\"js-inject-fake-cleaned\",\"label\":\"JS injection w\\/ fake \\\"cleaned\\/safe\\\" comment\",\"all\":[\"artifacts of previous malicious infection\",\"dangerous code has been removed\"]},{\"id\":\"linkforge-seo-injector\",\"label\":\"LinkForge SEO backlink injector\",\"all\":[\"linkforge.cc\"]},{\"id\":\"seo-doorway-cloak\",\"label\":\"SEO cloaking doorway (Thai gambling, fake sitemap)\",\"all\":[\"output_sitemap_page\",\"is_from_google\",\"send_404_and_exit\"]},{\"id\":\"helix-ultimate-xss\",\"label\":\"Helix Ultimate mega-menu XSS campaign\",\"any\":[\"xss.report\",\"_hu_inject\",\"_huinject\",\"sessionstorage._hxd\"]},{\"id\":\"gsocket-c2\",\"label\":\"gsocket reverse-shell C2 marker\",\"any\":[\"gs_args\"]},{\"id\":\"cloak-engine-thiscitze\",\"label\":\"thiscitze SEO cloaking engine\",\"all\":[\"thiscitze\"]},{\"id\":\"cloak-doorway-jsurl-jumpurl\",\"label\":\"Thai gambling SEO cloaking\\/doorway injector\",\"all\":[\"$js_url\",\"$jump_url\"]},{\"id\":\"cn-aes-loader\",\"label\":\"AES-decrypt + gzinflate eval loader\",\"all\":[\"openssl_decrypt\",\"gzinflate\",\"eval(\\\"?>\\\"\"]},{\"id\":\"cn-loader-tag\",\"label\":\"Chinese \'PHP code security loader\' tag\",\"all\":[\"php\\u4ee3\\u7801\\u5b89\\u5168\\u52a0\\u8f7d\\u5668\"]},{\"id\":\"menu-api-filemanager\",\"label\":\"MENU_API file-manager webshell\",\"all\":[\"menu_api_password\"]},{\"id\":\"remote-eval-curl\",\"label\":\"curl remote-fetch eval loader\",\"all\":[\"eval(\\\"?>\\\"\",\"curl_exec\"]},{\"id\":\"bujang-c2\",\"label\":\"Remote-fetch loader (bujang.online C2)\",\"all\":[\"bujang.online\"]},{\"id\":\"tinyfilemanager-tool\",\"label\":\"Tiny File Manager (webshell-capable file manager)\",\"all\":[\"tinyfilemanager\"]}],\"names\":[{\"id\":\"probe-d1337\",\"m\":[\"_d1337_\"],\"label\":\"d1337 write-access probe \\/ dropper marker\"},{\"id\":\"probe-write-test\",\"m\":[\"_probe_\"],\"label\":\"generic write-access probe marker (_probe_)\"}],\"scan_ext\":[],\"ack\":[\"6608daed700e0afc330788b2a272ca8d\",\"67b5f9a00c7aabf34261c715aeeaadba\",\"9812b693256a0c306cc53368559c7a4b\",\"ec96a3bed6681af996fd37f0818cba6b\",\"abfe3b7513994ae6ac2f33129b5f6e7b\",\"fb2e76c5ebafc2b8ea82e0d35d45fa02\",\"2ec54ce00420cd41dfae5abedc9edcb7\",\"02c1a767857c55d31cae7277bc43bac2\",\"573a5e7374be2925911b552d485a28f3\",\"cdf24443c39d943f8750d4a4420e6581\",\"99af93b919c5b6bc14a82382c39010ec\",\"55e704bb88a8f9ab0d756976c527516b\",\"981b4f5e07bf9cd1249d60d659e4ef93\",\"87d978102ed075a8e58074a0d3595c30\",\"85648deb8324a11400ecaebcfd04ae16\",\"323707d28051b4cbf161420f5f1bb499\",\"19104a261abbdffe7cd1713949b286cf\",\"a72013015988ad7d978ce9841a9668dd\",\"a8af9b93d27c774601e1d8a902145bd7\",\"82c8de717e67a620ca503a1a01a7d909\",\"a8192a3cf6279862054cb3092dad82bf\",\"eae8beb708347cfe54bf87506b572f41\",\"5db6f4cdd20dfee86e05110a2276d748\",\"872e97edc1d4247d2ed86d35f468ff88\",\"da9c67c9b7be2d5a7eb9113d76119abc\",\"d0c5a881e845f93a72e1450259de0d33\",\"ea531694f501221b61a324d3754da603\",\"b8333a512d949684c91c9dd907f9cb0c\",\"2c57aea21d161fe5761ffab0abff8228\",\"93117860cd06939707a4ff1797bebb40\",\"7f58961ebcc0db81b16c2d16072fb084\",\"760423f79cedc17e78df95505e93f0c7\",\"d8b0c0f2faf44495f7954fe826720bad\",\"b9b6b8553113e745ebef3251b5d223b9\",\"3e5d03ecb5de8ab2ff1790d7b78bee24\",\"0cd3f898084fe66b062ab5162d2b370c\",\"deb26b6603b6edd8381f6c77fc53cace\",\"0855cf0d6a33b86a8506aeeb769e4343\",\"bcfa5def6057812cba39996c13c1feb3\",\"b719915e7d46c753fe4aeb7a6b8e7fea\",\"913459ac4f3b49356595a341f9b2ac03\"],\"community\":0,\"fp\":[{\"all\":[\"easycalccheckplus\"],\"only\":[\"rce\"],\"id\":\"ecc-plus-doc-rce\"},{\"all\":[\"phpoffice\\\\phpspreadsheet\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"phpspreadsheet-lib\"},{\"any\":[\"cp_errordocument\",\"status-reason\"],\"not\":[\"<!--#exec\",\"<?\"],\"only\":[\"shtml\"],\"id\":\"plesk-error-shtml\"},{\"all\":[\"gumlet\",\"data:\\/\\/application\\/octet-stream\"],\"only\":[\"wrapper\"],\"id\":\"gumlet-imageresize-datawrapper\"},{\"all\":[\"data:\\/\\/image\",\"exif_read_data\"],\"only\":[\"wrapper\"],\"id\":\"exif-data-wrapper\"},{\"all\":[\"phpoffice\\\\phpword\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"phpword-lib\"},{\"all\":[\"box\\\\spout\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"box-spout-lib\"},{\"all\":[\"sarciszewski\\\\phpfuture\"],\"only\":[\"wrapper\"],\"id\":\"php-future-lib\"},{\"all\":[\"baformsmodelform\"],\"only\":[\"feed:upload-shell-uname-form\"],\"id\":\"fp-baforms-model\"},{\"all\":[\"quixnxt\"],\"only\":[\"goto\"],\"id\":\"fp-quix-goto\"},{\"all\":[\"varexporter\"],\"only\":[\"goto\"],\"id\":\"fp-symfony-varexporter-goto\"},{\"all\":[\"valorapps.com\"],\"only\":[\"idxbuild\"],\"id\":\"fp-easyfolderlisting-changelog\"},{\"all\":[\"matomo.org\"],\"only\":[\"rce\"],\"id\":\"fp-matomo-rce\"},{\"all\":[\"namespace tracy\"],\"only\":[\"phtml\"],\"id\":\"fp-tracy-phtml\"},{\"all\":[\"guzzlehttp\",\"requestfsm\"],\"only\":[\"goto\"],\"id\":\"fp-guzzle-requestfsm\"},{\"all\":[\"siteguarding.com\",\"siteguarding_server_ip1\"],\"only\":[\"feed:upload-shell-uname-form\"],\"id\":\"fp-siteguarding-agent\"},{\"all\":[\"muruguard\"],\"only\":[\"feed:helix-ultimate-xss\"],\"id\":\"fp-muruguard-scanner\"},{\"all\":[\"<svg\"],\"not\":[\"<script\",\"<?php\",\"<?=\",\"onload=\",\"onerror=\",\"onmouseover=\",\"onclick=\",\"onfocus=\",\"javascript:\",\"<foreignobject\"],\"only\":[\"tmp_exec\"],\"id\":\"fp-benign-svg-tmp\"}],\"seo\":{\"weights\":[],\"keywords\":[],\"sigs\":[]},\"recall\":[],\"fetched\":\"2026-07-31 00:02:41\",\"fetched_ts\":1785610638,\"etag\":\"\\\"6a6b92d9-1e99\\\"\",\"modified\":\"Thu, 30 Jul 2026 18:07:21 GMT\"},\"htp_incidents\":[]}'
WHERE `type` = 'component' AND `element` = 'com_htprotect'
| Status | Duration |
|---|
| Starting | 1.64 ms |
| checking permissions | 0.01 ms |
| Opening tables | 0.03 ms |
| After opening tables | 0.01 ms |
| System lock | 0.00 ms |
| table lock | 0.01 ms |
| init for update | 0.11 ms |
| Updating | 0.29 ms |
| End of update loop | 0.01 ms |
| Query end | 0.00 ms |
| Commit | 0.02 ms |
| Query end | 0.00 ms |
| closing tables | 0.00 ms |
| Unlocking tables | 0.00 ms |
| closing tables | 0.01 ms |
| Query end | 0.00 ms |
| Starting cleanup | 0.00 ms |
| Freeing items | 0.01 ms |
| Updating status | 0.04 ms |
| Reset for next command | 0.00 ms |
| # | Caller | Bestand en regelnummer |
|---|
| 10 | JDatabaseDriverMysqli->execute() | JROOT/administrator/components/com_htprotect/core/watch.php:1307 |
| 9 | HtpWatch::saveNotified() | JROOT/administrator/components/com_htprotect/core/watch.php:348 |
| 8 | HtpWatch::recordNotification() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3502 |
| 7 | PlgSystemHtprotectwatch->notify() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:3294 |
| 6 | PlgSystemHtprotectwatch->htpRun() | JROOT/plugins/system/htprotectwatch/htprotectwatch.php:266 |
| 5 | PlgSystemHtprotectwatch->onAfterRespond() | JROOT/libraries/joomla/event/event.php:70 |
| 4 | JEvent->update() | JROOT/libraries/joomla/event/dispatcher.php:160 |
| 3 | JEventDispatcher->trigger() | JROOT/libraries/src/Application/BaseApplication.php:108 |
| 2 | Joomla\CMS\Application\BaseApplication->triggerEvent() | JROOT/libraries/src/Application/CMSApplication.php:247 |
| 1 | Joomla\CMS\Application\CMSApplication->execute() | JROOT/index.php:49 |
2 × UPDATE `hmclx_extensions`
SET `params` = '{\"htp_shield\":{\"site_path\":\"\",\"sef_rules\":1,\"api_router\":1,\"api_mode\":\"route\",\"fastcgi_auth\":1,\"apache_options\":1,\"follow_symlink\":0,\"force_https\":1,\"www_mode\":0,\"canonical_host\":\"\",\"h_frame\":1,\"h_nosniff\":1,\"h_referrer\":\"strict-origin-when-cross-origin\",\"h_poweredby\":1,\"h_hsts\":0,\"h_hsts_sub\":0,\"h_coop\":0,\"h_permissions\":0,\"f_query\":1,\"f_rfi\":1,\"f_methods\":1,\"f_wpnoise\":1,\"htaccess_external\":0,\"shield_autoheal\":1,\"shield_autoheal_last\":0,\"mig_selfon_2415\":1,\"guard_dismissed\":0,\"x_shield\":1,\"x_sigs_off\":[],\"defs_version\":\"2026-07-15.9ac386\",\"mal_whitelist\":[],\"u_harden\":1,\"u_dirs\":[\"images\",\"media\"],\"emergency_lock\":0,\"notify_email\":\"pch.info@dubbelbit.nl\",\"notify_reminder_days\":14,\"unsub_secret\":\"knIOkiU01E3ceU0YZZ8ARjTQkWuTbqXAfktb1qjg6K0\",\"unsub_base\":\"https:\\/\\/www.efitec.nl\\/\",\"site_fp\":\"6d83c72d155aaa19f87ab9edd8cf222657b5b548\",\"swarm_contrib_id\":\"\",\"swarm_acked\":[],\"watch_manifest\":{\".htaccess\":\"dcb97f95087f2bdb336d0ffdcc300371ca6c4c51\",\"administrator\\/.htaccess\":\"2a00152a7d76a1d4a9444edf477c7404821a8b08\",\"images\\/.htaccess\":\"69714eb0929213f686d66baa144fceefbb395f8f\",\"media\\/.htaccess\":\"69714eb0929213f686d66baa144fceefbb395f8f\"},\"core_manifest\":{\"index.php\":\"2f1b60fc565276ae146bea9aaeadec93fb4dc87c\",\"administrator\\/index.php\":\"7078c5d7b2181900c509c93302f324e2dae228bf\"},\"core_jversion\":\"3.10.12\",\"accounts_watch\":1,\"account_baseline\":{\"613\":{\"id\":613,\"username\":\"admin\",\"email\":\"pch.info@dubbelbit.nl\",\"phash\":\"6300584d05e69c7f07ba2fb51a2f5ade41aeedd4\",\"block\":0,\"lastvisit\":\"2026-07-15 10:54:36\",\"pneeds\":0},\"800\":{\"id\":800,\"username\":\"dubbelbit\",\"email\":\"info@dubbelbit.nl\",\"phash\":\"081a5bae87c5a349a57ac9416a5157be4b8f95d5\",\"block\":0,\"lastvisit\":\"2025-11-06 17:15:16\",\"pneeds\":0}},\"admin_whitelist\":[],\"helix_ignore\":[],\"seo_watch\":1,\"compat_guard\":1,\"seo_cloaking_auto\":0,\"seo_whitelist\":[],\"seo_topic_ack\":[],\"seo_baseline\":{\"title\":\"Home\",\"out_domains\":{\"www.facebook.com\":1,\"nl.pinterest.com\":1,\"www.youtube.com\":1,\"www.s-bb.nl\":1,\"nieuw.efitec.nl\":1,\"xdebug.org\":1},\"shingles\":{\"511079512\":1,\"2918310184\":1,\"155886152\":1,\"3160688592\":1,\"3485062088\":1,\"585239104\":1,\"3828873704\":1,\"4087449296\":1,\"3631890208\":1,\"2453473432\":1,\"352088384\":1,\"1507055824\":1,\"1387258184\":1,\"96078016\":1,\"4120744744\":1,\"884599352\":1,\"148068952\":1,\"2322729328\":1,\"1647395640\":1,\"550572240\":1,\"2804985368\":1,\"2665301464\":1,\"3371643872\":1,\"1999195856\":1,\"412108984\":1,\"3675484672\":1,\"2196848680\":1,\"2599037872\":1,\"4081499304\":1,\"187337984\":1,\"362962264\":1,\"2094558736\":1,\"2787016200\":1,\"1792673952\":1,\"3358772584\":1,\"3190343216\":1,\"2235320368\":1,\"4225413856\":1,\"148784336\":1,\"4133289600\":1,\"1990767144\":1,\"265081816\":1,\"1454988472\":1,\"3545206312\":1,\"2836836760\":1,\"1552018832\":1,\"344452216\":1,\"461581872\":1,\"202494824\":1,\"3735037840\":1,\"3332537384\":1,\"2554787144\":1,\"746144872\":1,\"1848356288\":1,\"3951814824\":1,\"1464161728\":1,\"982788704\":1,\"3748426760\":1,\"136372440\":1,\"3214585776\":1,\"1332842344\":1,\"1366336928\":1,\"754226368\":1,\"1993946344\":1,\"140539032\":1,\"3458701480\":1,\"1779788808\":1,\"829495128\":1,\"258726864\":1,\"2313381704\":1,\"506576576\":1,\"682230128\":1,\"2799752896\":1,\"1200023392\":1,\"1387821168\":1,\"3867735952\":1,\"235572904\":1,\"211001480\":1,\"1209613064\":1,\"1950179312\":1,\"39928272\":1,\"2520740096\":1,\"810676984\":1,\"1550852192\":1,\"3946537872\":1,\"1061088320\":1,\"924937024\":1,\"2981285080\":1,\"4214313248\":1,\"2706907200\":1,\"4109595712\":1,\"2467453096\":1,\"1925217168\":1,\"254204696\":1,\"2797136096\":1,\"3557110600\":1,\"4041208904\":1,\"1327249520\":1,\"1607673584\":1,\"4007425464\":1,\"2632851624\":1,\"3330990656\":1,\"2693581640\":1,\"689915416\":1,\"4066896848\":1,\"480467872\":1,\"3008275536\":1,\"3101468488\":1,\"172199312\":1,\"650342624\":1,\"2553018880\":1,\"2609132040\":1,\"2991890336\":1,\"3462925544\":1,\"2964742568\":1,\"357174032\":1,\"1561660688\":1,\"1048480240\":1,\"1489547928\":1,\"208422712\":1,\"3778160000\":1,\"3789275216\":1,\"2776431456\":1,\"507422944\":1,\"4101744904\":1,\"942566752\":1,\"3196827536\":1,\"648166736\":1,\"1094268640\":1,\"1260128512\":1,\"3590796976\":1,\"1273715136\":1,\"4239054088\":1,\"1559046784\":1,\"4007417480\":1,\"7730296\":1,\"1458451704\":1,\"2911589176\":1,\"454621680\":1,\"1251844592\":1,\"4015838272\":1,\"1300147528\":1,\"1236487296\":1,\"3294019280\":1,\"4123225216\":1,\"670221008\":1,\"2571777288\":1,\"3627078176\":1,\"293222816\":1,\"281163600\":1,\"2508087208\":1,\"3543193024\":1,\"1915969656\":1,\"717056536\":1,\"848595304\":1,\"3107900104\":1,\"2589595704\":1,\"2034508136\":1,\"1977429088\":1,\"2584638584\":1,\"2493542936\":1,\"1158834928\":1,\"1531644320\":1,\"4102387360\":1,\"39764600\":1,\"4261163824\":1,\"1123389784\":1,\"2094010560\":1,\"1856123928\":1,\"376102376\":1,\"4096007544\":1,\"2256249280\":1,\"1618392856\":1,\"2709313920\":1,\"444641888\":1,\"3013023016\":1,\"4217705304\":1,\"2214186752\":1,\"716719120\":1,\"1972556728\":1,\"2438508112\":1,\"1820085032\":1,\"1223539912\":1,\"2846665840\":1,\"933003528\":1,\"2230427152\":1,\"1208455864\":1,\"2025534160\":1,\"1408784776\":1,\"2685059296\":1,\"3489792648\":1,\"1615724560\":1,\"8044840\":1,\"2316854528\":1,\"2550915448\":1,\"1211668720\":1,\"1935561680\":1,\"1828019016\":1,\"1827743704\":1,\"1337666672\":1,\"1911606592\":1,\"3178569384\":1,\"2552993816\":1,\"2123798152\":1,\"3761658400\":1,\"548688272\":1,\"2129684000\":1,\"4124423392\":1,\"1153004272\":1,\"796890520\":1,\"1247028480\":1,\"958748368\":1,\"1744512424\":1,\"647816080\":1,\"743882928\":1,\"3084540200\":1,\"3651199344\":1,\"109843936\":1,\"3303788176\":1,\"3393712720\":1,\"2772452800\":1,\"1345583752\":1,\"4138023008\":1,\"1630734352\":1,\"1587613576\":1,\"1950652592\":1,\"2777296976\":1,\"2621186584\":1,\"36106456\":1,\"2825573424\":1,\"303059736\":1,\"955024752\":1,\"4174757896\":1,\"335870296\":1,\"947878136\":1,\"885775072\":1,\"2836090264\":1,\"1479167544\":1,\"3195444184\":1,\"1373515616\":1,\"2703441304\":1,\"2999798000\":1,\"807202496\":1,\"2139078408\":1,\"3679148440\":1,\"4128820280\":1,\"4051291288\":1,\"524040760\":1,\"3226643448\":1,\"3914545768\":1,\"3485632672\":1,\"1455493656\":1,\"3040222736\":1,\"1738075592\":1,\"3987514200\":1,\"428036792\":1,\"2710735120\":1,\"3436957576\":1,\"3230827720\":1,\"1002378832\":1,\"477165832\":1,\"1378722152\":1,\"2798472384\":1,\"272556984\":1,\"351010464\":1,\"2168780672\":1,\"1806222752\":1,\"3716151024\":1,\"209155304\":1,\"2826036216\":1,\"420540632\":1,\"4203005848\":1,\"957468880\":1,\"1728849744\":1,\"4015778440\":1,\"1216866856\":1,\"4007963960\":1,\"3846677624\":1,\"3656753424\":1,\"75803256\":1,\"600705112\":1,\"1859028960\":1,\"2694091560\":1,\"2607914576\":1,\"2834052552\":1,\"3439897368\":1,\"2144818552\":1,\"3130333816\":1,\"3591606896\":1,\"1894249248\":1,\"4188555200\":1,\"245520800\":1,\"1682089672\":1,\"9149544\":1,\"3226699984\":1,\"1372800744\":1,\"2964205104\":1,\"722285192\":1,\"2322851088\":1,\"2139649696\":1,\"603889336\":1,\"3640799032\":1,\"1116378504\":1,\"3895415872\":1,\"1253935208\":1,\"528756504\":1,\"2284709784\":1,\"802473640\":1,\"3733678920\":1,\"361847392\":1,\"1232831160\":1,\"144058216\":1,\"1338885880\":1,\"992984272\":1,\"3773773072\":1,\"4182600\":1,\"2502992360\":1,\"4070217592\":1,\"547683160\":1,\"3290051432\":1,\"79724832\":1,\"821879880\":1,\"3181784208\":1,\"2105835160\":1,\"1048475128\":1,\"1530568368\":1,\"3978930832\":1,\"4141876912\":1,\"3134899488\":1,\"1235858440\":1,\"810201200\":1,\"3515040152\":1,\"2863190304\":1,\"1420257944\":1,\"798171424\":1,\"3843014608\":1,\"610676112\":1,\"1833740312\":1,\"3925377248\":1,\"2006124312\":1,\"3781864704\":1,\"3031336392\":1,\"4137422488\":1,\"3039953848\":1,\"1385104704\":1,\"4245224744\":1,\"4290332968\":1,\"2274655504\":1,\"1645581528\":1,\"2669455816\":1,\"3722712864\":1,\"1646278032\":1,\"2080430464\":1,\"1286501976\":1,\"1591713568\":1,\"1088809128\":1,\"3634194248\":1,\"3615937792\":1,\"3089178208\":1,\"3235297640\":1,\"1552428824\":1,\"1558271616\":1,\"2721862208\":1,\"1872388720\":1,\"1925908336\":1,\"1739818640\":1,\"1067862528\":1,\"4176326200\":1,\"1295895024\":1,\"1416323816\":1,\"252019184\":1,\"673687856\":1,\"1020035096\":1,\"1477984416\":1,\"798794864\":1,\"3895830512\":1,\"3877253568\":1,\"3725099576\":1,\"2100351152\":1,\"2474987096\":1,\"73942424\":1,\"13272208\":1,\"1943482168\":1,\"3977611416\":1,\"1547675656\":1,\"1718305248\":1,\"1732106904\":1,\"1643112200\":1,\"1345094056\":1,\"2907109104\":1,\"1613823168\":1,\"1646322024\":1},\"redirect_to\":\"\",\"ts\":1785610640},\"seo_overview_ts\":1785610637,\"seo_overview_finding\":[],\"core_overview_ts\":1784128054,\"core_overview_finding\":[],\"plugin_initialized\":1,\"quickicon_initialized\":1,\"autosecure\":0,\"autosecure_last\":0,\"tmp_autoclean\":0,\"tmp_keep\":[],\"autoupdate_notify\":0,\"autoupdate_ext\":1,\"autoupdate_all\":0,\"autoupdate_self\":1,\"autoupdate_manual\":0,\"autoupdate_mail_success\":0,\"autoupdate_include\":[],\"autoupdate_keep\":1,\"autoupdate_interval\":86400,\"autoupdate_schedule\":\"daily\",\"autoupdate_hour\":21,\"autoupdate_weekday\":5,\"autoupdate_grace\":3,\"autoupdate_malscan\":1,\"autoupdate_skip_major\":0,\"keep_update_sites\":1,\"keep_update_sites_except\":[],\"s_php\":1,\"s_types\":1,\"s_ext\":\"7z,avif,bmp,br,css,csv,doc,docx,eot,geojson,gif,gml,gpx,gz,htm,html,ico,ics,jp2,jpe,jpeg,jpg,js,json,kml,kmz,m4a,m4v,map,mjs,mov,mp3,mp4,mpeg,mpg,odp,ods,odt,oga,ogg,ogv,opus,otf,pdf,png,ppt,pptx,rar,rtf,svg,svgz,tif,tiff,ttf,txt,vtt,wasm,wav,webm,webmanifest,webp,woff,woff2,xls,xlsx,xml,xsl,zip\",\"s_files\":[\"administrator\\/components\\/com_akeeba\\/restore.php\",\"administrator\\/components\\/com_akeebabackup\\/restore.php\"],\"s_dirs_php\":[\"plugins\\/system\\/bfnetwork\"],\"s_dirs_static\":[],\"allow_paths\":[],\"s_dotfiles\":1,\"s_wellknown\":1,\"s_sensitive\":1,\"s_manifests\":0,\"s_sysdirs\":1,\"s_sysdirs_list\":[\"administrator\\/cache\",\"administrator\\/logs\",\"cache\",\"cli\",\"log\",\"logs\",\"tmp\"],\"p_compress\":1,\"p_precomp\":0,\"p_expires\":1,\"p_etag\":0,\"custom_top\":\"\",\"custom_bottom\":\"\",\"file_sha1\":\"dcb97f95087f2bdb336d0ffdcc300371ca6c4c51\",\"last_written\":\"2026-07-15 17:20:03\",\"last_test\":{\"checks\":[{\"label\":\"Home page reachable\",\"url\":\"https:\\/\\/www.efitec.nl\\/\",\"status\":200,\"ok\":true,\"note\":\"\"},{\"label\":\"Backend reachable (401 = password protection active)\",\"url\":\"https:\\/\\/www.efitec.nl\\/administrator\\/index.php\",\"status\":401,\"ok\":true,\"note\":\"\"},{\"label\":\"PHP shield active (test call is rejected with 403)\",\"url\":\"https:\\/\\/www.efitec.nl\\/htpx-canary-fbfbe897.php\\/htp\",\"status\":403,\"ok\":true,\"note\":\"\"},{\"label\":\"configuration.php blocked\",\"url\":\"https:\\/\\/www.efitec.nl\\/configuration.php\",\"status\":403,\"ok\":true,\"note\":\"\"}],\"regression\":false,\"reason\":\"\",\"time\":\"2026-07-15 15:20:03\"},\"guard_dir\":\"\",\"guard_recover\":\"263c210ee005a46813c42d75dd82d7144cb9b918b4356d8c60a8f9225963fe48\",\"welcome_sent\":1,\"welcome_green_since\":0,\"jed_review_ack\":\"\",\"jed_mail_last\":0,\"htaccess_cap\":[]},\"htp_defs\":{\"schema\":1,\"version\":\"2026-07-31.fa71fe\",\"signatures\":[{\"id\":\"jce-profiles-import\",\"label\":\"JCE Profil-Import (CVE-2026-48907)\",\"label_en\":\"JCE profile import (CVE-2026-48907)\",\"desc\":\"Unauthentifizierter Profil-Import im JCE-Editor - Beginn der aktuellen RCE-Kette (schaltet PHP-Uploads frei). Kein legitimer Frontend-Aufruf.\",\"desc_en\":\"Unauthenticated profile import in the JCE editor - start of the current RCE chain (enables PHP uploads). No legitimate frontend call.\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*task=profiles\\\\.import)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"jce-rpc-upload\",\"label\":\"JCE Webshell-Upload via plugin.rpc (CVE-2026-48907)\",\"label_en\":\"JCE webshell upload via plugin.rpc (CVE-2026-48907)\",\"desc\":\"Datei-Upload \\u00fcber den JCE-Dateibrowser (plugin.rpc, method=upload). Greift nur im Frontend; eingeloggte Autoren (legitimer Editor-Upload) bleiben unber\\u00fchrt.\",\"desc_en\":\"File upload via the JCE file browser (plugin.rpc, method=upload). Applies only
on the frontend; logged-in authors (legitimate editor upload) are unaffected.\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*task=plugin\\\\.rpc)(?=.*method=upload)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":null},{\"id\":\"jce-imgmanager\",\"label\":\"JCE Image Manager (Alt-Exploit)\",\"label_en\":\"JCE Image Manager (legacy exploit)\",\"desc\":\"Klassischer unauthentifizierter Datei-Upload \\u00fcber den JCE-Bildmanager (sehr alte JCE-Versionen).\",\"desc_en\":\"Classic unauthenticated file upload via the JCE image manager (very old JCE versions).\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*plugin=imgmanager)(?=.*method=form)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":null},{\"id\":\"novarain-nrframework\",\"label\":\"Novarain \\/ Tassos Framework (com_ajax include)\",\"label_en\":\"Novarain \\/ Tassos Framework (com_ajax include)\",\"desc\":\"CVE-2026-21627: unauthentifizierte PHP-Datei-Einbindung \\u00fcber plg_system_nrframework via com_ajax (task=include).\",\"desc_en\":\"CVE-2026-21627: unauthenticated PHP file inclusion via plg_system_nrframework through com_ajax (task=include).\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*nrframework)(?=.*task=include)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"astroid-ajax\",\"label\":\"Astroid Framework (AJAX-Endpunkt)\",\"label_en\":\"Astroid Framework (AJAX endpoint)\",\"desc\":\"CVE-2026-21628: ungepr\\u00fcfter Astroid-AJAX-Endpunkt (Upload\\/Installation). Coarse-Match auf com_ajax + astroid.\",\"desc_en\":\"CVE-2026-21628: unchecked Astroid AJAX endpoint (upload\\/installation). Coarse match
on com_ajax + astroid.\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*(plugin|template|view)=astroid)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"helix3-ajax\",\"label\":\"Helix3 (JoomShaper): unauth. com_ajax-Handler (Datei schreiben\\/l\\u00f6schen)\",\"label_en\":\"Helix3 (JoomShaper): unauth com_ajax handler (file write\\/delete)\",\"desc\":\"Helix3 < 3.1.1: der Ajax-Handler onAjaxHelix3 pr\\u00fcfte weder Login noch Rechte. Trifft gezielt die gef\\u00e4hrlichen Unauth-Aktionen im POST-Body: save (Layout-JSON ins aktive Template schreiben), remove (Datei l\\u00f6schen via Path-Traversal), import (Template-Style-Settings \\u00fcberschreiben) sowie upload_image\\/remove_image\\/updateFonts. Legitime Gast-Aktionen (voting, load) und eingeloggte Template-Nutzung \",\"desc_en\":\"Helix3 < 3.1.1: the onAjaxHelix3 ajax handler checked neither login nor permission. Targets the dangerous unauth POST-body actions: save (write layout JSON into the active template), remove (delete a file via path traversal), import (overwrite template style settings) plus upload_image\\/remove_image\\/updateFonts. Legitimate guest actions (voting, load)
and logged-in template use are unaffected. Fix:\",\"default\":1,\"qs\":\"data(?:\\\\[|%5b)action(?:\\\\]|%5d)=(?:save|remove|import|updatefonts)|action=(?:upload_image|remove_image)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"helix3-comajax\",\"label\":\"Helix3 (JoomShaper): unauth. com_ajax-Dispatcher (Datei-Write\\/Delete, Style-Injektion)\",\"label_en\":\"Helix3 (JoomShaper): unauth com_ajax dispatcher (file write\\/delete, style injection)\",\"desc\":\"Helix3 < 3.1.1: der Front-Dispatcher (option=com_ajax mit plugin=helix3) rief onAjaxHelix3 VOR jeder Token-\\/Rechtepr\\u00fcfung auf - unauthentifiziert save\\/import\\/remove\\/resetLayout\\/updateFonts\\/fontVariants (Datei-Schreiben, Path-Traversal-L\\u00f6schen, Template-Style-Injektion, Stored XSS). Blockt jeden GAST-Aufruf dieses Dispatchers im Frontend (Defense-in-Depth, f\\u00e4ngt auch laufende Scans) - erg\\u00e4nzt d\",\"desc_en\":\"Helix3 < 3.1.1: the front-end dispatcher (option=com_ajax with plugin=helix3) invoked onAjaxHelix3 BEFORE any token\\/permission check - unauthenticated save\\/import\\/remove\\/resetLayout\\/updateFonts\\/fontVariants (file write, path-traversal delete, template style injection, stored XSS). Blocks every GUEST call of this dispatcher
on the front end (defense in depth, also catches ongoing scans) - complemen\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*plugin=helix3\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"helixultimate-comajax\",\"label\":\"Helix Ultimate (JoomShaper): unauth. com_ajax-Dispatcher (Men\\u00fc-Write\\/Datei\\/Export)\",\"label_en\":\"Helix Ultimate (JoomShaper): unauth com_ajax dispatcher (menu write\\/file\\/export)\",\"desc\":\"Helix Ultimate < 2.2.7: der com_ajax-Handler onAjaxHelixultimate (option=com_ajax mit plugin=helixultimate, Action im task-Param) lief VOR jeder Login-\\/Rechtepr\\u00fcfung - ein anonymer Angreifer konnte in die Men\\u00fc-Einstellungen schreiben (Stored XSS bis in die Admin-Sitzung), Dateien per Path-Traversal beliebig l\\u00f6schen, einen Open Redirect ausl\\u00f6sen und das Template ungesch\\u00fctzt exportieren. Blockt\",\"desc_en\":\"Helix Ultimate < 2.2.7: the com_ajax handler onAjaxHelixultimate (option=com_ajax with plugin=helixultimate, action in the task param) ran BEFORE any login\\/permission check - an anonymous attacker could write into the menu settings (stored XSS reaching the admin session), delete files anywhere via path traversal, trigger an open redirect
and export the template unprotected. Blocks every GUEST call\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*plugin=helixultimate\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"comajax-include\",\"label\":\"com_ajax: Datei-Einbindung (generisch)\",\"label_en\":\"com_ajax: file inclusion (generic)\",\"desc\":\"F\\u00e4ngt unbekannte LFI-L\\u00fccken derselben Klasse ab: com_ajax mit task=include\\/require. Frontend.\",\"desc_en\":\"Catches unknown LFI holes of the same class: com_ajax with task=include\\/require. Frontend.\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*task=(include|require)(_once)?)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"sppagebuilder-uploadicon\",\"label\":\"SP Page Builder: unauthentifizierter Icon-Upload (RCE)\",\"label_en\":\"SP Page Builder: unauthenticated icon upload (RCE)\",\"desc\":\"Zero-Day in SP Page Builder bis 6.6.1: der asset-Controller (task=asset.uploadCustomIcon) hatte keinerlei Zugriffs-\\/Login-Pr\\u00fcfung - unauthentifizierter Datei-Upload nach \\/media\\/com_sppagebuilder\\/assets\\/iconfont\\/ - RCE. Nur Mini-WAF (G\\u00e4ste), da eingeloggte Builder den Endpunkt legitim nutzen.\",\"desc_en\":\"Zero-day in SP Page Builder up to 6.6.1: the asset controller (task=asset.uploadCustomIcon) had no access\\/login check - unauthenticated file upload to \\/media\\/com_sppagebuilder\\/assets\\/iconfont\\/ - RCE. Mini-WAF only (guests), since logged-in builders use the endpoint legitimately.\",\"default\":1,\"qs\":\"(?=.*option=com_sppagebuilder)(?=.*task=asset\\\\.uploadCustomIcon)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":null},{\"id\":\"dpcalendar-createdby-sqli\",\"label\":\"DPCalendar: unauth. SQL-Injection (Autor-Filter)\",\"label_en\":\"DPCalendar: unauth SQL injection (author filter)\",\"desc\":\"DPCalendar Blind-SQLi (Joomla 4.4-6 < 10.11.2, J3 < 8.19.4): der Frontend-Autor-Filter filter_created_by (option=com_dpcalendar, view=events) floss in skalarer Form ungecastet in a.created_by IN (...) - anonymes Auslesen beliebiger DB-Tabellen (nur lesend). Blockt Gast-Anfragen, deren filter_created_by kein reiner Integer ist (legitim = Autor-IDs\\/Ziffern) -> FP-frei. Fix 10.11.2 \\/ 8.19.4.\",\"desc_en\":\"DPCalendar blind SQLi (Joomla 4.4-6 < 10.11.2, J3 < 8.19.4): the front-end author filter filter_created_by (option=com_dpcalendar, view=events) flowed uncast into a.created_by IN (...) in its scalar form - anonymous read of arbitrary DB tables (read-only). Blocks guest requests whose filter_created_by is not a pure integer (legit = author IDs\\/digits) -> FP-free. Fix 10.11.2 \\/ 8.19.4.\",\"default\":1,\"qs\":\"(?=.*option=com_dpcalendar)(?=.*filter_created_by=[0-9,]*[^0-9,&])\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_dpcalendar\"},{\"id\":\"acym-entityselect-sqli\",\"label\":\"AcyMailing: unauth. SQL-Injection (Entity-Select Spaltenliste)\",\"label_en\":\"AcyMailing: unauth SQL injection (entity-select column list)\",\"desc\":\"CVE-2026-56292 (AcyMailing 6.0.0-10.11.0): der Frontend-Endpunkt EntitySelectController::loadEntityFront (option=com_acym, task=loadEntityFront) nahm die Request-Parameter columns\\/join_table ungeprueft in die SELECT-Spaltenliste von UserClass::getMatchingElements auf - ein anonymer Besucher konnte per Subquery beliebige DB-Tabellen (inkl. Passwort-Hashes) auslesen. Blockt GAST-Aufrufe dieses Tasks\",\"desc_en\":\"CVE-2026-56292 (AcyMailing 6.0.0-10.11.0): the front-end endpoint EntitySelectController::loadEntityFront (option=com_acym, task=loadEntityFront) placed the request parameters columns\\/join_table unchecked into the SELECT column list of UserClass::getMatchingElements - an anonymous visitor could read arbitrary DB tables (incl. password hashes) via a subquery. Blocks GUEST calls of this task whose c\",\"default\":1,\"qs\":\"(?=.*option=com_acym)(?=.*task=loadEntityFront)(?=.*(?:columns|join_table|join)=[^&]*(?:\\\\(|%28|%2528|\\\\s|%20|\\\\+))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_acym\"},{\"id\":\"quix-article-sqli\",\"label\":\"Quix Page Builder: unauth. SQL-Injection (Einzel-Artikel-AJAX)\",\"label_en\":\"Quix Page Builder: unauth SQL injection (single-article AJAX)\",\"desc\":\"Quix (ThemeXpert, Free UND Pro) bis 6.2.0, inkl. der 5.x-Reihe: der oeffentliche AJAX-Endpunkt (option=com_quix, task=ajax, element=joomla-article) ruft QuixJoomlaArticleElement::getAjax() ohne Login-\\/Token-\\/Lizenz-Pruefung; die Artikel-ID kommt base64-kodiert im data-Parameter und wird in articleExist() UNGECASTET in die DB-Query konkateniert -> unauthentifizierte, fehler-basierte SQL-Injection (\",\"desc_en\":\"Quix (ThemeXpert, Free
AND Pro) up to 6.2.0, incl. the 5.x line: the public AJAX endpoint (option=com_quix, task=ajax, element=joomla-article) calls QuixJoomlaArticleElement::getAjax() with no login\\/token\\/license check; the article id arrives base64-encoded in the data parameter
and is concatenated UNCAST into the DB query in articleExist() -> unauthenticated error-based SQL injection (CVSS 8.7). \",\"default\":1,\"qs\":\"(?=.*option=com_quix)(?=.*task=ajax\\\\b)(?=.*element=joomla-article\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_quix\"},{\"id\":\"joomcck-tags-sqli\",\"label\":\"JoomCCK: unauth. SQL-Injection (Tag-Verwaltung)\",\"label_en\":\"JoomCCK: unauth SQL injection (tag management)\",\"desc\":\"CVE-2026-49048 (JoomCCK 6.x vor 6.4.1): der Front-End-Task tags.save\\/tags.delete (option=com_joomcck) lief OHNE Token-\\/Login-\\/Rechte-Pruefung und schob den Request-Parameter tag (getString) roh - mit Double-Quote-Ausbruch - in ZWEI aufeinanderfolgende SQL-Statements (Existenz-SELECT + UPDATE). Ein anonymer Besucher konnte die Datenbank auslesen und veraendern (stacked\\/error-based SQLi). Blockt jed\",\"desc_en\":\"CVE-2026-49048 (JoomCCK 6.x before 6.4.1): the front-end task tags.save\\/tags.delete (option=com_joomcck) ran with NO token\\/login\\/permission check
and concatenated the request parameter tag (getString) raw - with a double-quote breakout - into TWO consecutive SQL statements (existence SELECT + UPDATE). An anonymous visitor could read
and modify the database (stacked\\/error-based SQLi). Blocks every \",\"default\":1,\"qs\":\"(?=.*option=com_joomcck)(?=.*task=tags\\\\.(?:save|delete))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_joomcck\"},{\"id\":\"gridbox-store-register\",\"label\":\"Balbooa Gridbox: unauth. Konto-Erstellung (store.register)\",\"label_en\":\"Balbooa Gridbox: unauth account creation (store.register)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, gemeldet 2026-07-28, Fix in 2.20.2 (29.07.2026). Der Front-End-Task store.register lief OHNE Login\\/Token und legte ein Joomla-Konto mit FREI WAEHLBARER Usergruppe plus sofort gueltiger Session an (unauth Privilege Escalation). Blockt jeden Gast-Aufruf dieses Tasks. Kosten: falls die Site die Gridbox-eigene Frontend-Registrierung nu\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to
and incl. 2.20.1 - actively exploited, reported 2026-07-28, fixed in 2.20.2 (29 Jul 2026). The front-end task store.register ran WITHOUT login\\/token
and created a Joomla account with an ARBITRARY usergroup plus an immediately valid session (unauth privilege escalation). Blocks every guest call of this task. Cost: if the site uses Gridbox front-end registration (\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=store(\\\\.|%2e)register)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":\"com_gridbox\"},{\"id\":\"gridbox-uploader-showimage-read\",\"label\":\"Balbooa Gridbox: unauth. Datei-Lesen (uploader.showImage)\",\"label_en\":\"Balbooa Gridbox: unauth arbitrary file read (uploader.showImage)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, Fix in 2.20.2 (29.07.2026). Der Front-End-Task uploader.showImage laed ohne Login den Query-Parameter image= und gibt bei Nicht-Bildern die Datei roh aus (fopen+fpassthru) -> unauth Arbitrary File Read, u. a. configuration.php. Trifft JEDE Gridbox-Installation. SURGICAL: greift NUR, wenn image= ein Angriffsmuster enthaelt (Pfad-Kle\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to
and incl. 2.20.1 - actively exploited, fixed in 2.20.2 (29 Jul 2026). The front-end task uploader.showImage reads the query parameter image= without login
and, for non-images, dumps the file raw (fopen+fpassthru) -> unauth arbitrary file read incl. configuration.php. Hits EVERY Gridbox install. SURGICAL: fires ONLY when image= contains an attack pattern (travers\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=uploader(\\\\.|%2e)showImage)(?=.*image=(?:%2f|\\/|[a-z]:|[a-z]%3a|[^&]*(?:\\\\.\\\\.|%2e%2e|\\\\.php|%2ephp|%00|php:|php%3a|:%2f%2f|:\\/\\/)))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":\"com_gridbox\"},{\"id\":\"gridbox-uploader-savephoto\",\"label\":\"Balbooa Gridbox: unauth. Datei-Schreiben (uploader.savePhotoEditorImage)\",\"label_en\":\"Balbooa Gridbox: unauth arbitrary file write (uploader.savePhotoEditorImage)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, Fix in 2.20.2 (29.07.2026). Der Front-End-Task uploader.savePhotoEditorImage schreibt eine beliebige Datei (inkl. .php) in den Webroot; der Zieldateiname liegt im POST-Body (php:\\/\\/input) und ist fuer die .htaccess unsichtbar, und eingeloggte Redakteure nutzen den Endpunkt legitim. Daher waf_only + scope=guest: NUR im Echtzeit-Plugi\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to
and incl. 2.20.1 - actively exploited, fixed in 2.20.2 (29 Jul 2026). The front-end task uploader.savePhotoEditorImage writes an arbitrary file (incl. .php) into the webroot; the target filename is in the POST body (php:\\/\\/input), invisible to .htaccess,
and logged-in editors use the endpoint legitimately. Hence waf_only + scope=guest: enforced ONLY in the real-t\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=uploader(\\\\.|%2e)savePhotoEditorImage)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_gridbox\"},{\"id\":\"baforms-signature-rce\",\"label\":\"Balbooa Forms: unauth. RCE (Signature-Feld, CVE-2026-65880)\",\"label_en\":\"Balbooa Forms: unauth RCE (signature field, CVE-2026-65880)\",\"desc\":\"Balbooa Forms (com_baforms) bis inkl. 2.4.2.1 - CVE-2026-65880 (CVSS 10.0), aktiv ausgenutzt, Fix erst 2.4.3. Beim Absenden eines Formulars mit SIGNATURE-Feld (task=form.sendMessage) verwendet FormModel::saveSignature den vom Angreifer im Feld-JSON gelieferten Funktionsnamen dynamisch als aufgerufene Funktion mit angeh\\u00e4ngtem Wert - unauthentifizierte Remote Code Execution. Der legitime Wert ist i\",\"desc_en\":\"Balbooa Forms (com_baforms) up to
and incl. 2.4.2.1 - CVE-2026-65880 (CVSS 10.0), actively exploited, fixed only in 2.4.3. Submitting a form with a SIGNATURE field (task=form.sendMessage) makes FormModel::saveSignature use the attacker-supplied function name
from the field JSON dynamically as the called function with an appended value - unauthenticated remote code execution. The legitimate value i\",\"default\":1,\"qs\":\"(?=.*\\\\bmethod[^a-z0-9]{1,6}(?:system|exec|shell_exec|passthru|assert|popen|proc_open|pcntl_exec|file_get_contents|readfile|show_source|highlight_file|fopen|scandir|phpinfo|eval|create_function|call_user_func)\\\\b)(?=.*\\\\bimage\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":1,\"trigger\":\"com_baforms\"},{\"id\":\"traversal-encoded\",\"label\":\"Pfad-Klettern (kodierte Varianten)\",\"label_en\":\"Path traversal (encoded variants)\",\"desc\":\"Erg\\u00e4nzt den Standard-Filter um Umgehungstricks: ....\\/\\/ , doppelte Kodierung (%252e), %c0%ae, %2e%2e%5c.\",\"desc_en\":\"Extends the standard filter with bypass tricks: ....\\/\\/ , double encoding (%252e), %c0%ae, %2e%2e%5c.\",\"default\":1,\"qs\":\"(\\\\.{3,}\\/|%252e|%c0%a[ef]|%2e%2e%5c|\\\\.\\\\.%5c)\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"php-wrapper-uri\",\"label\":\"PHP-Stream-Wrapper im Pfad\",\"label_en\":\"PHP stream wrapper in the path\",\"desc\":\"Blockiert php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ , expect:\\/\\/ u. a. direkt im angefragten Pfad.\",\"desc_en\":\"Blocks php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ , expect:\\/\\/ etc. directly in the requested path.\",\"default\":1,\"qs\":null,\"uri\":\"(?:php|phar|data|expect|glob|zlib|zip):\\/\",\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"api-config-leak\",\"label\":\"Joomla-API Konfigurations-Leak\",\"label_en\":\"Joomla API configuration leak\",\"desc\":\"CVE-2023-23752: sch\\u00fctzt den Endpunkt \\/api\\/...\\/v1\\/config\\/application auch ohne komplette API-Sperre.\",\"desc_en\":\"CVE-2023-23752: protects the \\/api\\/...\\/v1\\/config\\/application endpoint even without a complete API block.\",\"default\":1,\"qs\":null,\"uri\":\"^api\\/index\\\\.php\\/v[0-9]+\\/config\",\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"php-object-injection\",\"label\":\"PHP Object Injection (serialisierte Payload)\",\"label_en\":\"PHP object injection (serialised payload)\",\"desc\":\"Serialisiertes PHP-Objekt in einem Parameter (O:\\/C:<L\\u00e4nge>:) - typischer Einstieg f\\u00fcr Object-Injection\\/POP-Ketten. Kommt in normalen Anfragen nicht vor.\",\"desc_en\":\"Serialised PHP object in a parameter (O:\\/C:<length>:) - typical entry point for object injection\\/POP chains. Does not occur in normal requests.\",\"default\":1,\"qs\":\"(?<![a-z0-9])[oc]:[0-9]{1,4}:\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"stream-wrapper-param\",\"label\":\"PHP-Stream-Wrapper in Parameter\",\"label_en\":\"PHP stream wrapper in a parameter\",\"desc\":\"php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ u. a. als Parameterwert - LFI\\/RCE-Vektor. Erg\\u00e4nzt die Pfad-Variante (php-wrapper-uri).\",\"desc_en\":\"php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ etc. as a parameter value - LFI\\/RCE vector. Complements the path variant (php-wrapper-uri).\",\"default\":1,\"qs\":\"(php|phar|data|expect|glob|zlib|zip):\\/{2}\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"param-traversal\",\"label\":\"Pfad-Klettern im Parameter\",\"label_en\":\"Path traversal in a parameter\",\"desc\":\"Mehrfaches ..\\/ als Parameterwert - generisches Directory-Traversal\\/LFI in beliebigen Komponenten.\",\"desc_en\":\"Repeated ..\\/ as a parameter value - generic directory traversal\\/LFI in any component.\",\"default\":1,\"qs\":\"=(\\\\.\\\\.\\/){2,}\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null}],\"vuln_extensions\":[{\"element\":\"aimycaptchalessformguard\",\"type\":\"plugin\",\"folder\":\"captcha\",\"name\":\"Aimy Captcha-Less Form Guard\",\"below\":\"20.1\",\"above\":\"17.0\",\"severity\":\"high\",\"note\":\"Sicherheitsl\\u00fccke in 18.0 bis 20.0, vom Hersteller in 20.1 behoben (freie und PRO-Edition betroffen). Kein Workaround - auf Aimy Captcha-Less Form Guard 20.1 oder neuer aktualisieren.\",\"note_en\":\"Security issue in 18.0 to 20.0, fixed by the vendor in 20.1 (free
and PRO edition affected). No workaround - update to Aimy Captcha-Less Form Guard 20.1 or newer.\",\"advisory\":\"https:\\/\\/www.aimy-extensions.com\\/joomla\\/captcha-less-form-guard.html\",\"advisory_en\":\"https:\\/\\/www.aimy-extensions.com\\/joomla\\/captcha-less-form-guard.html\"},{\"element\":\"com_easystore\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EasyStore (JoomShaper)\",\"below\":\"2.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere unauthentifizierte SQL-Injections (CVE-2026-65759 ff.). Auf EasyStore 2.0.2 oder neuer aktualisieren.\",\"note_en\":\"Multiple unauthenticated SQL injections (CVE-2026-65759 ff.). Update to EasyStore 2.0.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65759\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65759\"},{\"element\":\"com_splms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP LMS (JoomShaper)\",\"below\":\"4.1.4\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-48909: unauth. Code-Ausf\\u00fchrung durch unsichere Cookie-Deserialisierung. Auf SP LMS 4.1.4 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48909: unauthenticated code execution via insecure cookie deserialization. Update to SP LMS 4.1.4 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-48909\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-48909\"},{\"element\":\"com_osmembership\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Membership Pro (JoomDonation)\",\"below\":\"4.6.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-62415: kritische L\\u00fccke durch unsichere Standardkonfiguration. Auf Membership Pro 4.6.2 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-62415: critical flaw caused by an insecure default configuration. Update to Membership Pro 4.6.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-62415\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-62415\"},{\"element\":\"com_convertforms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Convert Forms (Tassos)\",\"below\":\"5.2.3\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische L\\u00fccken bis 5.2.2 (Datei-L\\u00f6schung, Datenleck; CVE-2024-40744). Auf Convert Forms 5.2.3 oder neuer aktualisieren.\",\"note_en\":\"Multiple critical flaws up to 5.2.2 (arbitrary file deletion, data exposure; CVE-2024-40744). Update to Convert Forms 5.2.3 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2024-40744\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2024-40744\"},{\"element\":\"sourcerer\",\"type\":\"plugin\",\"folder\":\"editors-xtd\",\"name\":\"Sourcerer (Regular Labs)\",\"below\":\"12.2.9\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2025-22204: Code-Injection durch mangelnde Rechtepr\\u00fcfung. Auf Sourcerer 12.2.9 oder neuer aktualisieren.\",\"note_en\":\"CVE-2025-22204: code injection due to missing permission checks. Update to Sourcerer 12.2.9 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-22204\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-22204\"},{\"element\":\"com_easydiscuss\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EasyDiscuss (StackIdeas)\",\"below\":\"5.0.16\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-21625: ACL-Umgehung im JSON-Output (Zugriff auf gesch\\u00fctzte Forendaten). Auf EasyDiscuss 5.0.16 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21625: access-control bypass in the JSON output exposing protected forum data. Update to EasyDiscuss 5.0.16 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-21625\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-21625\"},{\"element\":\"com_komento\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Komento (StackIdeas)\",\"below\":\"4.0.8\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2025-54294: SQL-Injection, ausnutzbar durch unprivilegierte Nutzer. Auf Komento 4.0.8 oder neuer aktualisieren.\",\"note_en\":\"CVE-2025-54294: SQL injection exploitable by unprivileged users. Update to Komento 4.0.8 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-54294\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-54294\"},{\"element\":\"nrframework\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Novarain \\/ Tassos Framework\",\"below\":\"6.0.38\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-21627: unauthentifizierte PHP-Einbindung via com_ajax. Auf 6.0.38 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21627: unauthenticated PHP inclusion via com_ajax. Update to 6.0.38 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/joomla-tassos-framework-novarain-framework-sicherheitsluecke\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/joomla-tassos-framework-novarain-framework-sicherheitsluecke\"},{\"element\":\"astroid\",\"type\":\"library\",\"folder\":\"\",\"name\":\"Astroid Framework\",\"below\":\"3.3.11\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-21628: unauthentifizierter Datei-Upload via AJAX-Endpunkt (Dropper in \\/images\\/). Auf 3.3.13 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21628: unauthenticated file upload via AJAX endpoint (dropper in \\/images\\/). Update to 3.3.13 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/joomla-astroid-framework-sicherheitsluecke-vulnerability\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/joomla-astroid-framework-sicherheitsluecke-vulnerability\"},{\"element\":\"helix3\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Helix3 (JoomShaper)\",\"below\":\"3.1.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Unauthentifizierter com_ajax-Handler (onAjaxHelix3) ohne Login-\\/Rechtepr\\u00fcfung: Angreifer k\\u00f6nnen Dateien ins aktive Template schreiben oder per Path-Traversal l\\u00f6schen (save\\/remove\\/import). Auf Helix3 3.1.1 oder neuer aktualisieren.\",\"note_en\":\"Unauthenticated com_ajax handler (onAjaxHelix3) with no login or permission check: attackers can write files into the active template or delete files via path traversal (save\\/remove\\/import). Update to Helix3 3.1.1 or newer.\",\"advisory\":\"https:\\/\\/htprotect.org\\/helix3\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/helix3\"},{\"element\":\"helixultimate\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Helix Ultimate (JoomShaper)\",\"below\":\"2.2.7\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Kritische unauth. L\\u00fccke in ALLEN Versionen < 2.2.7: der com_ajax-Handler onAjaxHelixultimate lief VOR jeder Rechtepr\\u00fcfung - anonym in die Men\\u00fcs schreiben (Stored XSS in den Admin), Path-Traversal-L\\u00f6schen, Open Redirect, Template-Export. Auf 2.2.7 updaten (Plugin UND Template). HTProtects Mini-WAF blockt den Aufruf bereits. NICHT mit Helix3 verwechseln.\",\"note_en\":\"Critical unauth flaw in ALL versions below 2.2.7: the com_ajax handler onAjaxHelixultimate ran before any permission check - anonymous menu writes (stored XSS reaching the admin), path-traversal delete, open redirect, template export. Update to 2.2.7 (plugin
AND template). HTProtect mini-WAF already blocks the call. Not to be confused with Helix3.\",\"advisory\":\"https:\\/\\/htprotect.org\\/helix-ultimate\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/helix-ultimate\"},{\"element\":\"com_baforms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Balbooa Forms\",\"below\":\"2.4.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Aktiver Zero-Day (RCE), ALLE Versionen bis 2.4.0: der Upload-Endpoint form.uploadAttachmentFile pr\\u00fcft weder Login\\/Token noch Dateityp - ein anonymer Angreifer kann eine PHP-Datei hochladen und ausf\\u00fchren. NOCH KEIN Patch. Sofortma\\u00dfnahme: Upload-Formulare depublizieren. HTProtects Gast-Upload-Schutz blockt den ausf\\u00fchrbaren Upload bereits.\",\"note_en\":\"Active zero-day (RCE), ALL versions up to 2.4.0: the upload endpoint form.uploadAttachmentFile checks neither login\\/token nor file type - an anonymous attacker can upload
and run a PHP file. NO patch yet. Interim: unpublish forms with upload fields. The HTProtect guest-upload filter already blocks the executable upload.\",\"advisory\":\"https:\\/\\/htprotect.org\\/balbooa-forms\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/balbooa-forms\"},{\"element\":\"com_jce\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JCE Editor\",\"below\":\"2.9.99.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-48907: unauthentifizierter Webshell-Upload (profiles.import + plugin.rpc). Dringend auf JCE 2.9.99.6 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48907: unauthenticated webshell upload (profiles.import + plugin.rpc). Urgently update to JCE 2.9.99.6 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/jce-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/jce-sicherheitsluecke-joomla\"},{\"element\":\"com_rsfiles\",\"type\":\"component\",\"folder\":\"\",\"name\":\"RSFiles!\",\"below\":\"1.17.12\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Aktiver unauthentifizierter Datei-Upload -> RCE, ALLE Versionen bis 1.17.11: der Frontend-Upload (task=rsfiles.upload) pr\\u00fcft weder Login\\/Token noch Dateiendung - ein anonymer Angreifer l\\u00e4dt eine .php nach \\/downloads bzw. \\/briefcase und f\\u00fchrt sie aus. Dringend auf 1.17.12 aktualisieren. HTProtects Gast-Upload-Schutz blockt den ausf\\u00fchrbaren Upload bereits.\",\"note_en\":\"Active unauthenticated file upload -> RCE, ALL versions up to 1.17.11: the front-end upload (task=rsfiles.upload) checks neither login\\/token nor file extension - an anonymous attacker uploads a .php into \\/downloads or \\/briefcase
and executes it. Update to 1.17.12 urgently. The HTProtect guest-upload filter already blocks the executable upload.\",\"advisory\":\"https:\\/\\/www.rsjoomla.com\\/blog\\/view\\/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html\",\"advisory_en\":\"https:\\/\\/www.rsjoomla.com\\/blog\\/view\\/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html\"},{\"element\":\"com_edocman\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EDocman\",\"below\":\"3.9\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Unauthentifizierte SQL-Injection (alle Versionen bis 3.8): ein anonymer Besucher schleust ueber einen Filter-Parameter eines oeffentlichen Frontend-Endpunkts SQL in eine ungequotete DB-Abfrage ein und kann die Datenbank auslesen (bis hin zu Zugangsdaten). Der genaue Vektor ist bewusst nicht veroeffentlicht. Dringend auf EDocman 3.9.0 aktualisieren.\",\"note_en\":\"Unauthenticated SQL injection (all versions up to 3.8): an anonymous visitor injects SQL through a filter parameter of a public front-end endpoint into an unquoted DB query
and can read the database (up to credentials). The exact vector is deliberately undisclosed. Update to EDocman 3.9.0 urgently.\",\"advisory\":\"https:\\/\\/joomdonation.com\\/forum\\/edocman\\/82813-edocman-3-9-0-security-release---important-update-recommended.html\",\"advisory_en\":\"https:\\/\\/joomdonation.com\\/forum\\/edocman\\/82813-edocman-3-9-0-security-release---important-update-recommended.html\"},{\"element\":\"com_foranalytics\",\"type\":\"component\",\"folder\":\"\",\"name\":\"4Analytics\",\"below\":\"5.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Zwei unauthentifizierte Sicherheitsluecken (CVE-2026-57833 + CVE-2026-58077) in ALLEN Versionen vor 5.0.2 - ein anonymer Angreifer braucht keinen Login. Hersteller Weeblr stuft beide als kritisch ein; technische Details sind 7 Tage embargoed. Dringend auf 4Analytics 5.0.2 aktualisieren (laeuft auf Joomla 3-6).\",\"note_en\":\"Two unauthenticated security flaws (CVE-2026-57833 + CVE-2026-58077) in ALL versions before 5.0.2 - an anonymous attacker needs no login. Vendor Weeblr rates both critical; technical details are under a 7-day embargo. Update to 4Analytics 5.0.2 urgently (runs
on Joomla 3-6).\",\"advisory\":\"https:\\/\\/weeblr.com\\/blog\\/critical-vulnerabilities-2026-07-15\",\"advisory_en\":\"https:\\/\\/weeblr.com\\/blog\\/critical-vulnerabilities-2026-07-15\"},{\"element\":\"com_quix\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Quix\",\"below\":\"6.2.1\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Unauthentifizierte SQL-Injection (Free UND Pro, alle Versionen vor 6.2.1 \\u2013 auch die 5.x-Reihe): ein anonymer Besucher kann die gesamte Datenbank auslesen (CVSS 8.7). HTProtects Mini-WAF blockt den Angriff bereits aktiv. Auf Quix 6.2.1 aktualisieren (Free erh\\u00e4lt 6.2.1 ebenfalls \\u00fcber die Update-Funktion).\",\"note_en\":\"Unauthenticated SQL injection (Free
AND Pro, all versions below 6.2.1 \\u2013 including the 5.x line): an anonymous visitor can read the entire database (CVSS 8.7). HTProtect\'s mini-WAF already actively blocks the attack. Update to Quix 6.2.1 (Free receives 6.2.1 too via the update function).\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/quix-sql-injection-disclosure\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/quix-sql-injection-disclosure\\/\"},{\"element\":\"com_joomcck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JoomCCK\",\"below\":\"6.4.1\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"Unauthentifizierte SQL-Injection (CVE-2026-49048, JoomCCK 6.x vor 6.4.1): der Front-End-Task \\u201eTag speichern\\/l\\u00f6schen\\\" pr\\u00fcfte weder Login noch Token und \\u00fcbernahm den Parameter \\u201etag\\\" ungefiltert in zwei SQL-Abfragen - ein anonymer Besucher konnte die Datenbank auslesen und ver\\u00e4ndern. HTProtects Mini-WAF blockt den unautorisierten Gast-Aufruf bereits aktiv. Dringend auf JoomCCK 6.4.1 aktualisi\",\"note_en\":\"Unauthenticated SQL injection (CVE-2026-49048, JoomCCK 6.x before 6.4.1): the front-end \\\"save\\/delete tag\\\" task checked neither login nor token
and took the \\\"tag\\\" parameter unfiltered into two SQL queries - an anonymous visitor could read
and modify the database. HTProtect\'s mini-WAF already actively blocks the unauthorized guest call. Update to JoomCCK 6.4.1 urgently.\",\"advisory\":\"https:\\/\\/github.com\\/JoomCoder-com\\/JoomCCK\\/releases#release-6.4.1\",\"advisory_en\":\"https:\\/\\/github.com\\/JoomCoder-com\\/JoomCCK\\/releases#release-6.4.1\"},{\"element\":\"com_chronoforms8\",\"type\":\"component\",\"folder\":\"\",\"name\":\"ChronoForms\",\"below\":\"8.0.53\",\"above\":\"8.0.0\",\"severity\":\"high\",\"note\":\"Unauthentifizierte gespeicherte XSS (CVE-2026-58148, ChronoForms 8.x vor 8.0.53): ein anonymer Besucher schleust \\u00fcber ein Formular-Feld JavaScript ein, das ungefiltert gespeichert und sp\\u00e4ter - z. B. beim Ansehen der Einsendungen im Backend - ausgef\\u00fchrt wird, bis hin zur \\u00dcbernahme der Admin-Sitzung (CVSS 8.7). Auf ChronoForms 8.0.53 aktualisieren.\",\"note_en\":\"Unauthenticated stored XSS (CVE-2026-58148, ChronoForms 8.x before 8.0.53): an anonymous visitor injects JavaScript via a form field that is stored unfiltered
and later executed - e.g. when viewing the submissions in the backend - up to takeover of the admin session (CVSS 8.7). Update to ChronoForms 8.0.53.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-58148\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-58148\"},{\"element\":\"com_jdownloads\",\"type\":\"component\",\"folder\":\"\",\"name\":\"jDownloads\",\"below\":\"4.1.6\",\"above\":\"4.1.0\",\"severity\":\"high\",\"note\":\"Unauthentifizierte Datei-Upload-L\\u00fccke (jDownloads 4.1.0-4.1.5): eine verwaiste Uploader-Datei (upload-handler.php) pr\\u00fcft weder Login noch Token und l\\u00e4sst einen anonymen Besucher beliebige Dateien - u. a. exe\\/msi\\/Archive - in einen Ordner der Site schreiben; auf manchen Servern bis zur Codeausf\\u00fchrung, sonst Malware-Hosting\\/Speicher-Flutung. HTProtects .htaccess-Schutzschild blockt den direkten \",\"note_en\":\"Unauthenticated file upload flaw (jDownloads 4.1.0-4.1.5): a leftover uploader file (upload-handler.php) checks neither login nor token
and lets an anonymous visitor write arbitrary files - incl. exe\\/msi\\/archives - into a folder
on the site; up to remote code execution
on some servers, otherwise malware hosting \\/ disk flooding. HTProtect\'s .htaccess shield already blocks direct access to the file \",\"advisory\":\"https:\\/\\/www.jdownloads.com\\/index.php\\/news\\/jdownloads-4-1-6-secure-update-released.html\",\"advisory_en\":\"https:\\/\\/www.jdownloads.com\\/index.php\\/news\\/jdownloads-4-1-6-secure-update-released.html\"},{\"element\":\"com_dpcalendar\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DPCalendar\",\"below\":\"10.11.2\",\"above\":\"9.0.0\",\"severity\":\"high\",\"note\":\"DPCalendar (Joomla 4.4-6, 9.0.0-10.11.1): unauthentifizierte Blind-SQL-Injection - der Autor-Filter filter_created_by (Frontend view=events) floss in skalarer Form ohne Integer-Cast in die Query (a.created_by IN ...); ein anonymer Besucher kann beliebige DB-Tabellen AUSLESEN (nichts \\u00e4ndern). Dringend auf 10.11.2 aktualisieren. HTProtects Mini-WAF blockt die Injektion bereits.\",\"note_en\":\"DPCalendar (Joomla 4.4-6, 9.0.0-10.11.1): unauthenticated blind SQL injection - the author filter filter_created_by (front-end view=events) flowed uncast (scalar form) into the query (a.created_by IN ...); an anonymous visitor can READ arbitrary DB tables (no writes). Update to 10.11.2 urgently. HTProtect mini-WAF already blocks the injection.\",\"advisory\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\",\"advisory_en\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\"},{\"element\":\"com_dpcalendar\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DPCalendar\",\"below\":\"8.19.4\",\"above\":\"8.18.0\",\"severity\":\"high\",\"note\":\"DPCalendar Joomla-3-Linie (8.x), 8.18.0-8.19.3: dieselbe unauth Blind-SQL-Injection \\u00fcber den Autor-Filter filter_created_by (skalar, ohne Integer-Cast, nur lesend). In 8.19.4 (Joomla-3-Fix) behoben. Auf 8.19.4 aktualisieren. HTProtects Mini-WAF blockt die Injektion bereits.\",\"note_en\":\"DPCalendar Joomla 3 line (8.x), 8.18.0-8.19.3: same unauth blind SQL injection via the author filter filter_created_by (scalar, no integer cast, read-only). Fixed in 8.19.4 (Joomla 3 fix). Update to 8.19.4. HTProtect mini-WAF already blocks the injection.\",\"advisory\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\",\"advisory_en\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\"},{\"element\":\"com_phocadownload\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Download\",\"below\":\"6.1.3\",\"above\":\"6.0.0\",\"severity\":\"high\",\"note\":\"Authentifizierter Datei-Upload -> RCE (Versionen 6.0 bis 6.1.2): ein eingeloggter Nutzer mit Zugriff auf die Upload-Funktion kann eine ausf\\u00fchrbare Datei (z. B. .php) hochladen und ausf\\u00fchren. In 6.1.3 (Security-Release) behoben - auf 6.1.3 oder neuer aktualisieren. HTProtects PHP-Schild verhindert die Ausf\\u00fchrung einer hochgeladenen PHP-Datei in den Upload-Ordnern bereits.\",\"note_en\":\"Authenticated file upload -> RCE (versions 6.0 to 6.1.2): a logged-in user with access to the upload feature can upload
and run an executable file (e.g. .php). Fixed in 6.1.3 (security release) - update to 6.1.3 or newer. The HTProtect PHP shield already prevents execution of an uploaded PHP file in the upload folders.\",\"advisory\":\"https:\\/\\/www.phoca.cz\\/news\\/1481-phoca-download-version-6-1-3-released-security-release\",\"advisory_en\":\"https:\\/\\/www.phoca.cz\\/news\\/1481-phoca-download-version-6-1-3-released-security-release\"},{\"element\":\"com_phocamaps\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Maps\",\"below\":\"6.1.0\",\"above\":\"5.0.0\",\"severity\":\"medium\",\"note\":\"CVE-2026-65763: reflektiertes XSS (5.0.0-6.0.4) durch unzureichende Eingabepr\\u00fcfung - ein Angreifer bringt einen Besucher \\u00fcber einen pr\\u00e4parierten Link dazu, eingeschleustes JavaScript auszuf\\u00fchren. Auf Phoca Maps 6.1.0 (Security-Release) oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-65763: reflected XSS (5.0.0-6.0.4) via improper input validation - an attacker lures a visitor with a crafted link to run injected JavaScript. Update to Phoca Maps 6.1.0 (security release) or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65763\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65763\"},{\"element\":\"com_phocaguestbook\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Guestbook\",\"below\":\"6.1.1\",\"above\":\"5.0.0\",\"severity\":\"medium\",\"note\":\"CVE-2026-65762: reflektiertes XSS (5.0.0-6.1.0) durch unzureichende Eingabepr\\u00fcfung - ein pr\\u00e4parierter Link f\\u00fchrt beim Besucher eingeschleustes JavaScript aus. Auf Phoca Guestbook 6.1.1 (Security-Release) oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-65762: reflected XSS (5.0.0-6.1.0) via improper input validation - a crafted link runs injected JavaScript in the visitor\'s browser. Update to Phoca Guestbook 6.1.1 (security release) or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65762\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65762\"},{\"element\":\"com_acym\",\"type\":\"component\",\"folder\":\"\",\"name\":\"AcyMailing 6+\",\"below\":\"10.11.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"AcyMailing Neuauflage (6+): CVE-2026-56292 unauthentifizierte SQL-Injection (6.0.0-10.11.0) - ein anonymer Angreifer liest beliebige DB-Tabellen inkl. Passwort-Hashes (CVSS 8.7). \\u00c4ltere L\\u00fccken: CVE-2023-28731 unauth Upload\\/RCE unter 8.3.0, CVE-2026-3614 Rechteausweitung 9.11.0-10.8.1. Dringend auf 10.11.1 aktualisieren.\",\"note_en\":\"AcyMailing new line (6+): CVE-2026-56292 unauthenticated SQL injection (6.0.0-10.11.0) - an anonymous attacker reads arbitrary DB tables incl. password hashes (CVSS 8.7). Older holes: CVE-2023-28731 unauth upload\\/RCE below 8.3.0, CVE-2026-3614 privilege escalation 9.11.0-10.8.1. Update to 10.11.1 urgently.\",\"advisory\":\"https:\\/\\/htprotect.org\\/acymailing\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/acymailing\"},{\"element\":\"com_acymailing\",\"type\":\"component\",\"folder\":\"\",\"name\":\"AcyMailing Classic\",\"below\":\"4.9.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"AcyMailing Classic (End-of-Life): \\u00e4ltere Versionen mit kritischen L\\u00fccken - unauthentifizierter Datei-Upload der 3.x-\\u00c4ra (RCE, z. B. 3.9.0) sowie Backend-SQL-Injection CVE-2015-7338 (in 4.9.5 behoben). Auf eine unterst\\u00fctzte AcyMailing-Version migrieren. (Die 5.x-Linie hat keine bekannte sehr kritische L\\u00fccke; CSV-Injection CVE-2018-9107 in 5.9.1-5.9.5 ist niedrig\\/client-seitig.)\",\"note_en\":\"AcyMailing Classic (end-of-life): older versions with critical holes - unauthenticated file upload of the 3.x era (RCE, e.g. 3.9.0)
and backend SQL injection CVE-2015-7338 (fixed in 4.9.5). Migrate to a supported AcyMailing version. (The 5.x line has no known very critical hole; CSV injection CVE-2018-9107 in 5.9.1-5.9.5 is low\\/client-side.)\",\"advisory\":\"https:\\/\\/htprotect.org\\/acymailing\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/acymailing\"},{\"element\":\"com_igallery\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Ignite Gallery\",\"below\":\"5.4.1\",\"above\":\"5.0.0\",\"severity\":\"high\",\"note\":\"Ignite Gallery 5.0.0 bis 5.4.0: Stored XSS (hoch) durch fehlendes Output-Escaping beim Hochladen\\/Bearbeiten von Bildern, dazu SSRF (ungefilterte Video-URL) und eine Rechteausweitung beim Download geschuetzter\\/unveroeffentlichter Bilder. Ausnutzbar von Nutzern MIT Upload-\\/Bearbeitungsrecht (Frontend oder Backend). Auf 5.4.1 oder neuer aktualisieren.\",\"note_en\":\"Ignite Gallery 5.0.0 to 5.4.0: stored XSS (high) via missing output escaping when uploading\\/editing images, plus SSRF (unfiltered video URL)
and a privilege escalation when downloading restricted\\/unpublished images. Exploitable by users WITH upload\\/edit permission (frontend or backend). Update to 5.4.1 or newer.\",\"advisory\":\"https:\\/\\/www.ignitegallery.com\\/documentation\\/changelog\",\"advisory_en\":\"https:\\/\\/www.ignitegallery.com\\/documentation\\/changelog\"},{\"element\":\"com_icagenda\",\"type\":\"component\",\"folder\":\"\",\"name\":\"iCagenda\",\"below\":\"4.0.8\",\"above\":\"4.0.0\",\"severity\":\"critical\",\"note\":\"CVE-2026-48939 (4.x-Linie 4.0.0-4.0.7): das Event-Formular (task=submit.submit) pr\\u00fcft nur das CSRF-Token, keine Zugriffsrechte - anonymer Datei-Upload. Voller RCE nur auf Joomla 6 (Core blockt .php nicht mehr); auf Joomla <=5 mildert der Core-Filter, die Zugriffsl\\u00fccke bleibt. Dringend auf 4.0.8 aktualisieren. HTProtects Dateischild verhindert die Ausf\\u00fchrung bereits.\",\"note_en\":\"CVE-2026-48939 (4.x line 4.0.0-4.0.7): the event form (task=submit.submit) checks only the CSRF token, no access rights - anonymous file upload. Full RCE only
on Joomla 6 (core no longer blocks .php);
on Joomla <=5 the core filter mitigates but the access flaw remains. Update to 4.0.8 urgently. The HTProtect file shield already prevents execution.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/icagenda-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/icagenda-sicherheitsluecke-joomla\"},{\"element\":\"com_icagenda\",\"type\":\"component\",\"folder\":\"\",\"name\":\"iCagenda\",\"below\":\"3.9.15\",\"above\":\"3.2.1\",\"severity\":\"critical\",\"note\":\"CVE-2026-48939, 3.x-Linie 3.2.1-3.9.14: dieselbe Zugriffsl\\u00fccke im Event-Formular (task=submit.submit, keine Rechtepr\\u00fcfung, anonymer Datei-Upload). In 3.9.15 (Security-Backport f\\u00fcr Joomla 3) behoben. Dringend auf 3.9.15 aktualisieren. HTProtects Dateischild verhindert die Ausf\\u00fchrung bereits. (Voller RCE v. a. auf Joomla 6.)\",\"note_en\":\"CVE-2026-48939, 3.x line 3.2.1-3.9.14: same access-control flaw in the event form (task=submit.submit, no permission check, anonymous file upload). Fixed in 3.9.15 (security backport for Joomla 3). Update to 3.9.15 urgently. The HTProtect file shield already prevents execution. (Full RCE mainly
on Joomla 6.)\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/icagenda-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/icagenda-sicherheitsluecke-joomla\"},{\"element\":\"com_sppagebuilder\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP Page Builder\",\"below\":\"6.7.1\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"Unauthentifizierte SQL-Injection (CVE-2026-65766) bis Version 6.7.0: ein anonymer Besucher liest \\u00fcber einen ungefilterten Parameter (direction) im Dynamic-Content-Endpunkt beliebige Datenbank-Tabellen aus - bis zu Benutzerkonten, Passwort-Hashes und dem Seiten-Geheimnis (CVSS 8.7). Dazu ein offenes Mail-Relay (CVE-2026-65877): Angreifer verschicken \\u00fcber die Kontaktformular-Addons beliebige E-Mai\",\"note_en\":\"Unauthenticated SQL injection (CVE-2026-65766) up to version 6.7.0: via an unfiltered parameter (direction) in the Dynamic Content endpoint an anonymous visitor can read arbitrary database tables - down to user accounts, password hashes
and the site secret (CVSS 8.7). Plus an open mail relay (CVE-2026-65877): attackers send arbitrary emails with a spoofed sender through the contact-form addons. Up\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/sp-page-builder-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/sp-page-builder-sicherheitsluecke-joomla\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.6\",\"above\":\"3.5.0\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) bis 3.5.10: ein Front-End-Upload-Endpunkt (zum Hinzuf\\u00fcgen von Bildern) pr\\u00fcfte nur das CSRF-Token, aber keine Zugriffsrechte und keinen Dateityp - ein nicht eingeloggter Angreifer konnte eine beliebige Datei (z. B. PHP-Shell) in einen frei w\\u00e4hlbaren Ordner hochladen und ausf\\u00fchren (Remote Code Execution). Dringend auf 3.6.0 aktualisieren. (HTProtects generischer Upload-Sch\",\"note_en\":\"Critical flaw (RCE) up to 3.5.10: a front-end upload endpoint (for adding images) only verified the CSRF token but no access rights
and no file type - an unauthenticated attacker could upload an arbitrary file (e.g. a PHP shell) into a freely chosen folder
and execute it (remote code execution). Update to 3.6.0 urgently. (The HTProtect generic upload protection already blocks the unauthenticated u\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.4.10\",\"above\":\"3.2.0\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) in der Joomla-4-Linie unter 3.4.10: unauthentifizierter Datei-Upload \\u00fcber einen Front-End-Endpunkt (nur CSRF-Token, keine Zugriffs-\\/Typpr\\u00fcfung) - beliebige Datei in frei w\\u00e4hlbaren Ordner hochladbar und ausf\\u00fchrbar. In 3.4.10 (Backport) behoben. Dringend aktualisieren. (HTProtects generischer Upload-Schutz blockt den unauthentifizierten Upload bereits; das Dateischild verh\",\"note_en\":\"Critical flaw (RCE) in the Joomla 4 line below 3.4.10: unauthenticated file upload via a front-end endpoint (CSRF token only, no access\\/type check) - arbitrary file uploadable into a freely chosen folder
and executable. Fixed in 3.4.10 (backport). Update urgently. (The HTProtect generic upload protection already blocks the unauthenticated upload; the file shield additionally prevents execution.)\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.1.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Kritische L\\u00fccke (RCE) in der Joomla-3-Linie unter 3.1.1: unauthentifizierter Datei-Upload \\u00fcber einen Front-End-Endpunkt (nur CSRF-Token, keine Zugriffs-\\/Typpr\\u00fcfung) - beliebige Datei in frei w\\u00e4hlbaren Ordner hochladbar und ausf\\u00fchrbar. In 3.1.1 (Backport f\\u00fcr Joomla 3) behoben. Dringend aktualisieren. (HTProtects generischer Upload-Schutz blockt den unauthentifizierten Upload bereits; das Date\",\"note_en\":\"Critical flaw (RCE) in the Joomla 3 line below 3.1.1: unauthenticated file upload via a front-end endpoint (CSRF token only, no access\\/type check) - arbitrary file uploadable into a freely chosen folder
and executable. Fixed in 3.1.1 (backport for Joomla 3). Update urgently. (The HTProtect generic upload protection already blocks the unauthenticated upload; the file shield additionally prevents ex\",\"advisory\":\"\",\"advisory_en\":\"\"},{\"element\":\"com_eventbooking\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Events Booking\",\"below\":\"5.8.1\",\"above\":\"5.0\",\"severity\":\"medium\",\"note\":\"Zwei Sicherheitsl\\u00fccken ohne Anmeldung in allen Versionen der 5er-Reihe vor 5.8.1: Erstens konnte jeder anonyme Besucher \\u00fcber die Datei-Upload-Funktion des Anmeldeformulars Dateien auf dem Server ablegen - ohne Konto, ohne Anmeldung und ohne Sicherheitstoken; die Funktion war ab Werk in jeder Installation aktiv. Die abgelegten Dateien lie\\u00dfen sich anschlie\\u00dfend unter einem vorhersehbaren Namen wi\",\"note_en\":\"Two unauthenticated security flaws in all versions of the 5.x line below 5.8.1: First, any anonymous visitor could place files
on the server through the file upload of the registration form - no account, no login, no security token; the feature was enabled by default in every installation. The uploaded files could then be retrieved again under a predictable name. Program files were not allowed in \",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/events-booking-unauthenticated-upload-user-enumeration\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/events-booking-unauthenticated-upload-user-enumeration\\/\"},{\"element\":\"com_djclassifieds\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DJ-Classifieds\",\"below\":\"3.11.2\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Schwerwiegende L\\u00fccke in allen Versionen bis einschlie\\u00dflich 3.11.1: Die Funktion zum Hochladen von Anzeigenbildern nahm Dateien entgegen, ohne dass eine Anmeldung n\\u00f6tig war und ohne die \\u00fcblichen Sicherheitspr\\u00fcfungen. Angreifer konnten dadurch eine Schaddatei auf der Website ablegen und im ung\\u00fcnstigen Fall die Kontrolle \\u00fcber die gesamte Seite \\u00fcbernehmen. Die L\\u00fccke wurde bereits aktiv ausgen\",\"note_en\":\"Serious flaw in all versions up to
and including 3.11.1: the image upload used for classified ads accepted files without requiring a login
and without the usual security checks. This allowed attackers to place a malicious file
on the website
and, in the worst
case, take control of the entire site. The flaw was already being actively exploited before a fix was available. Update to version 3.11.2 or\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/dj-classifieds-unauthenticated-file-upload\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/dj-classifieds-unauthenticated-file-upload\\/\"},{\"element\":\"com_gridbox\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Gridbox\",\"below\":\"2.20.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Balbooa hat in zwei Schritten reagiert: 2.20.1 (20.07.2026) schloss eine kritische Anmelde-L\\u00fccke (CVE-2026-61425), blieb aber unvollst\\u00e4ndig. Erst 2.20.2 (29.07.2026) behebt - laut Hersteller in allen Versionen bis einschlie\\u00dflich 2.20.1 - unbefugten Dateizugriff (Lesen und Schreiben), das rekursive L\\u00f6schen ganzer Ordner, mehrere SQL-Einschleusungen, weitere Umgehungen der Rechtepr\\u00fcfung und Inf\",\"note_en\":\"Balbooa responded in two steps: 2.20.1 (20 Jul 2026) closed a critical authentication flaw (CVE-2026-61425) but was incomplete. Only 2.20.2 (29 Jul 2026) fixes - across all versions up to
and including 2.20.1, per the vendor - unauthorized file access (read
and write), recursive deletion of whole directories, multiple SQL injections, further authorization-check bypasses
and information disclosure.\",\"advisory\":\"https:\\/\\/www.balbooa.com\\/blog\\/gridbox\\/gridbox-2-20-2-security-release\",\"advisory_en\":\"https:\\/\\/www.balbooa.com\\/blog\\/gridbox\\/gridbox-2-20-2-security-release\"}],\"php_min\":\"8.1\",\"fetched\":\"2026-08-01 01:42:25\",\"fetched_ts\":1785615665,\"etag\":\"\\\"6a6d343c-f907\\\"\",\"modified\":\"Fri, 31 Jul 2026 23:48:12 GMT\",\"joomla_latest\":{\"3\":\"3.10.12\",\"4\":\"4.4.14\",\"5\":\"5.4.7\",\"6\":\"6.1.2\"},\"joomla_latest_ts\":1785590511,\"joomla_latest_try\":1785590511},\"htp_malware\":{\"schema\":1,\"version\":\"2026-07-29.671bb5\",\"sigs\":[{\"id\":\"backdoor-prepend-sshkey\",\"all\":[\"auto_prepend_file\",\"authorized_keys\"]},{\"id\":\"cred-stealer-ctfaudit\",\"any\":[\"x-ctf-audit\",\"jlib_audit_gid\"]},{\"id\":\"upload-shell-form\",\"all\":[\"move_uploaded_file\",\"check directory permissions\"]},{\"id\":\"sppb-iconfont-shell\",\"any\":[\"sppbwhoami\"]},{\"id\":\"remote-eval-loader\",\"all\":[\"eval(\\\"?>\\\"\"],\"any\":[\"fetchcontentfromurl\",\"file_get_contents(\\\"http\",\"file_get_contents(\'http\"]},{\"id\":\"seo-doorway-slot\",\"any\":[\"slot gacor\",\"situs slot gacor\"]},{\"id\":\"filemanager-backdoor-data\",\"all\":[\"<?php exit;?>{\",\"\\\"groupinfo\\\"\",\"\\\"sizemax\\\"\"]},{\"id\":\"encrypted-eval-openssl\",\"all\":[\"openssl_raw_data\",\"aes-256-cbc\"],\"not\":[\"openssl_decrypt\",\"openssl_encrypt\"]},{\"id\":\"0xnix-split-encrypted\",\"all\":[\"0xnix encrypted code\"]},{\"id\":\"upload-shell-devco1\",\"all\":[\"move_uploaded_file\",\"devco1\"]},{\"id\":\"upload-shell-uname-form\",\"all\":[\"move_uploaded_file\",\"php_uname\",\"multipart\\/form-data\"]},{\"id\":\"hacktool-adminer\",\"all\":[\"adminer_errors\",\"idf_unescape\"]},{\"id\":\"webshell-range-obfuscator\",\"all\":[\"\\\"r\\\".\\\"a\\\".\\\"n\\\".\\\"g\\\".\\\"e\\\"\",\"eval\"]},{\"id\":\"webshell-md5quad-gate\",\"all\":[\"md5(md5(md5(md5(\",\"eval\"]},{\"id\":\"remote-loader-stream-include\",\"any\":[\"include stream_get_meta_data\",\"require stream_get_meta_data\",\"include(stream_get_meta_data\",\"require(stream_get_meta_data\"]},{\"id\":\"webshell-dual-uploader\",\"all\":[\"remote_url\",\"name=\\\"_upl\\\"\",\"name=\\\"_remote\\\"\"]},{\"id\":\"webshell-comment-obfuscator\",\"all\":[\"-*\\/\\/\\/\",\"\\\"~\\\"\"]},{\"id\":\"eval-openssl-shell\",\"label\":\"eval(openssl_decrypt) webshell\",\"all\":[\"eval(openssl_decrypt(\"]},{\"id\":\"dropper-drivergenius-c2\",\"label\":\"Remote-fetch dropper (drivergenius C2)\",\"all\":[\"drivergenius.it.com\"]},{\"id\":\"dropper-backdate-disguise\",\"label\":\"Remote-fetch dropper (mtime-forge + disguise)\",\"all\":[\"getreferencefiletime\",\"generatefilename\"]},{\"id\":\"js-inject-fake-cleaned\",\"label\":\"JS injection w\\/ fake \\\"cleaned\\/safe\\\" comment\",\"all\":[\"artifacts of previous malicious infection\",\"dangerous code has been removed\"]},{\"id\":\"linkforge-seo-injector\",\"label\":\"LinkForge SEO backlink injector\",\"all\":[\"linkforge.cc\"]},{\"id\":\"seo-doorway-cloak\",\"label\":\"SEO cloaking doorway (Thai gambling, fake sitemap)\",\"all\":[\"output_sitemap_page\",\"is_from_google\",\"send_404_and_exit\"]},{\"id\":\"helix-ultimate-xss\",\"label\":\"Helix Ultimate mega-menu XSS campaign\",\"any\":[\"xss.report\",\"_hu_inject\",\"_huinject\",\"sessionstorage._hxd\"]},{\"id\":\"gsocket-c2\",\"label\":\"gsocket reverse-shell C2 marker\",\"any\":[\"gs_args\"]},{\"id\":\"cloak-engine-thiscitze\",\"label\":\"thiscitze SEO cloaking engine\",\"all\":[\"thiscitze\"]},{\"id\":\"cloak-doorway-jsurl-jumpurl\",\"label\":\"Thai gambling SEO cloaking\\/doorway injector\",\"all\":[\"$js_url\",\"$jump_url\"]},{\"id\":\"cn-aes-loader\",\"label\":\"AES-decrypt + gzinflate eval loader\",\"all\":[\"openssl_decrypt\",\"gzinflate\",\"eval(\\\"?>\\\"\"]},{\"id\":\"cn-loader-tag\",\"label\":\"Chinese \'PHP code security loader\' tag\",\"all\":[\"php\\u4ee3\\u7801\\u5b89\\u5168\\u52a0\\u8f7d\\u5668\"]},{\"id\":\"menu-api-filemanager\",\"label\":\"MENU_API file-manager webshell\",\"all\":[\"menu_api_password\"]},{\"id\":\"remote-eval-curl\",\"label\":\"curl remote-fetch eval loader\",\"all\":[\"eval(\\\"?>\\\"\",\"curl_exec\"]},{\"id\":\"bujang-c2\",\"label\":\"Remote-fetch loader (bujang.online C2)\",\"all\":[\"bujang.online\"]},{\"id\":\"tinyfilemanager-tool\",\"label\":\"Tiny File Manager (webshell-capable file manager)\",\"all\":[\"tinyfilemanager\"]}],\"names\":[{\"id\":\"probe-d1337\",\"m\":[\"_d1337_\"],\"label\":\"d1337 write-access probe \\/ dropper marker\"},{\"id\":\"probe-write-test\",\"m\":[\"_probe_\"],\"label\":\"generic write-access probe marker (_probe_)\"}],\"scan_ext\":[],\"ack\":[\"6608daed700e0afc330788b2a272ca8d\",\"67b5f9a00c7aabf34261c715aeeaadba\",\"9812b693256a0c306cc53368559c7a4b\",\"ec96a3bed6681af996fd37f0818cba6b\",\"abfe3b7513994ae6ac2f33129b5f6e7b\",\"fb2e76c5ebafc2b8ea82e0d35d45fa02\",\"2ec54ce00420cd41dfae5abedc9edcb7\",\"02c1a767857c55d31cae7277bc43bac2\",\"573a5e7374be2925911b552d485a28f3\",\"cdf24443c39d943f8750d4a4420e6581\",\"99af93b919c5b6bc14a82382c39010ec\",\"55e704bb88a8f9ab0d756976c527516b\",\"981b4f5e07bf9cd1249d60d659e4ef93\",\"87d978102ed075a8e58074a0d3595c30\",\"85648deb8324a11400ecaebcfd04ae16\",\"323707d28051b4cbf161420f5f1bb499\",\"19104a261abbdffe7cd1713949b286cf\",\"a72013015988ad7d978ce9841a9668dd\",\"a8af9b93d27c774601e1d8a902145bd7\",\"82c8de717e67a620ca503a1a01a7d909\",\"a8192a3cf6279862054cb3092dad82bf\",\"eae8beb708347cfe54bf87506b572f41\",\"5db6f4cdd20dfee86e05110a2276d748\",\"872e97edc1d4247d2ed86d35f468ff88\",\"da9c67c9b7be2d5a7eb9113d76119abc\",\"d0c5a881e845f93a72e1450259de0d33\",\"ea531694f501221b61a324d3754da603\",\"b8333a512d949684c91c9dd907f9cb0c\",\"2c57aea21d161fe5761ffab0abff8228\",\"93117860cd06939707a4ff1797bebb40\",\"7f58961ebcc0db81b16c2d16072fb084\",\"760423f79cedc17e78df95505e93f0c7\",\"d8b0c0f2faf44495f7954fe826720bad\",\"b9b6b8553113e745ebef3251b5d223b9\",\"3e5d03ecb5de8ab2ff1790d7b78bee24\",\"0cd3f898084fe66b062ab5162d2b370c\",\"deb26b6603b6edd8381f6c77fc53cace\",\"0855cf0d6a33b86a8506aeeb769e4343\",\"bcfa5def6057812cba39996c13c1feb3\",\"b719915e7d46c753fe4aeb7a6b8e7fea\",\"913459ac4f3b49356595a341f9b2ac03\"],\"community\":0,\"fp\":[{\"all\":[\"easycalccheckplus\"],\"only\":[\"rce\"],\"id\":\"ecc-plus-doc-rce\"},{\"all\":[\"phpoffice\\\\phpspreadsheet\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"phpspreadsheet-lib\"},{\"any\":[\"cp_errordocument\",\"status-reason\"],\"not\":[\"<!--#exec\",\"<?\"],\"only\":[\"shtml\"],\"id\":\"plesk-error-shtml\"},{\"all\":[\"gumlet\",\"data:\\/\\/application\\/octet-stream\"],\"only\":[\"wrapper\"],\"id\":\"gumlet-imageresize-datawrapper\"},{\"all\":[\"data:\\/\\/image\",\"exif_read_data\"],\"only\":[\"wrapper\"],\"id\":\"exif-data-wrapper\"},{\"all\":[\"phpoffice\\\\phpword\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"phpword-lib\"},{\"all\":[\"box\\\\spout\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"box-spout-lib\"},{\"all\":[\"sarciszewski\\\\phpfuture\"],\"only\":[\"wrapper\"],\"id\":\"php-future-lib\"},{\"all\":[\"baformsmodelform\"],\"only\":[\"feed:upload-shell-uname-form\"],\"id\":\"fp-baforms-model\"},{\"all\":[\"quixnxt\"],\"only\":[\"goto\"],\"id\":\"fp-quix-goto\"},{\"all\":[\"varexporter\"],\"only\":[\"goto\"],\"id\":\"fp-symfony-varexporter-goto\"},{\"all\":[\"valorapps.com\"],\"only\":[\"idxbuild\"],\"id\":\"fp-easyfolderlisting-changelog\"},{\"all\":[\"matomo.org\"],\"only\":[\"rce\"],\"id\":\"fp-matomo-rce\"},{\"all\":[\"namespace tracy\"],\"only\":[\"phtml\"],\"id\":\"fp-tracy-phtml\"},{\"all\":[\"guzzlehttp\",\"requestfsm\"],\"only\":[\"goto\"],\"id\":\"fp-guzzle-requestfsm\"},{\"all\":[\"siteguarding.com\",\"siteguarding_server_ip1\"],\"only\":[\"feed:upload-shell-uname-form\"],\"id\":\"fp-siteguarding-agent\"},{\"all\":[\"muruguard\"],\"only\":[\"feed:helix-ultimate-xss\"],\"id\":\"fp-muruguard-scanner\"},{\"all\":[\"<svg\"],\"not\":[\"<script\",\"<?php\",\"<?=\",\"onload=\",\"onerror=\",\"onmouseover=\",\"onclick=\",\"onfocus=\",\"javascript:\",\"<foreignobject\"],\"only\":[\"tmp_exec\"],\"id\":\"fp-benign-svg-tmp\"}],\"seo\":{\"weights\":[],\"keywords\":[],\"sigs\":[]},\"recall\":[],\"fetched\":\"2026-07-31 00:02:41\",\"fetched_ts\":1785610638,\"etag\":\"\\\"6a6b92d9-1e99\\\"\",\"modified\":\"Thu, 30 Jul 2026 18:07:21 GMT\"},\"htp_incidents\":[]}'
1 × INSERT INTO `hmclx_session` (`session_id`,`guest`,`time`,`userid`,`username`,`client_id`)
VALUES (X'383539616c6d353261726c646539706e347470313639326b3430', 1, 1785615663, 0, '', 0
1 × UPDATE `hmclx_extensions`
SET `params` = '{\"mediaversion\":\"b0336a8a9c63513e913ac4104303536c\"}'
1 × SHOW FULL COLUMNS
FROM `hmclx_sppagebuilder
1 × UPDATE hmclx_sppagebuilder
SET `hits` = (`hits` + 1)
1 × UPDATE `hmclx_session`
SET `data` = 'joomla|s:840:\"TzoyNDoiSm9vbWxhXFJlZ2lzdHJ5XFJlZ2lzdHJ5IjozOntzOjc6IgAqAGRhdGEiO086ODoic3RkQ2xhc3MiOjE6e3M6OToiX19kZWZhdWx0IjtPOjg6InN0ZENsYXNzIjo0OntzOjc6InNlc3Npb24iO086ODoic3RkQ2xhc3MiOjM6e3M6NzoiY291bnRlciI7aToxO3M6NToidGltZXIiO086ODoic3RkQ2xhc3MiOjM6e3M6NToic3RhcnQiO2k6MTc4NTYxNTY2MztzOjQ6Imxhc3QiO2k6MTc4NTYxNTY2MztzOjM6Im5vdyI7aToxNzg1NjE1NjYzO31zOjU6InRva2VuIjtzOjMyOiJjQmdCMXplSWxpOTRmeGVQbDc3T05UYktybkxlYUlQZCI7fXM6ODoicmVnaXN0cnkiO086MjQ6Ikpvb21sYVxSZWdpc3RyeVxSZWdpc3RyeSI6Mzp7czo3OiIAKgBkYXRhIjtPOjg6InN0ZENsYXNzIjowOnt9czoxNDoiACoAaW5pdGlhbGl6ZWQiO2I6MDtzOjk6InNlcGFyYXRvciI7czoxOiIuIjt9czo0OiJ1c2VyIjtPOjIwOiJKb29tbGFcQ01TXFVzZXJcVXNlciI6MTp7czoyOiJpZCI7aTowO31zOjI1OiJwbGdfc3lzdGVtX2xhbmd1YWdlZmlsdGVyIjtPOjg6InN0ZENsYXNzIjoxOntzOjg6Imxhbmd1YWdlIjtzOjU6Im5sLU5MIjt9fX1zOjE0OiIAKgBpbml0aWFsaXplZCI7YjowO3M6OToic2VwYXJhdG9yIjtzOjE6Ii4iO30=\";' , `time` = 1785615665