VERKLAREN niet mogelijk voor zoekopdracht: UPDATE `hmclx_extensions`
SET `params` = '{\"htp_shield\":{\"site_path\":\"\",\"sef_rules\":1,\"api_router\":1,\"api_mode\":\"route\",\"fastcgi_auth\":1,\"apache_options\":1,\"follow_symlink\":0,\"force_https\":1,\"www_mode\":0,\"canonical_host\":\"\",\"h_frame\":1,\"h_nosniff\":1,\"h_referrer\":\"strict-origin-when-cross-origin\",\"h_poweredby\":1,\"h_hsts\":0,\"h_hsts_sub\":0,\"h_coop\":0,\"h_permissions\":0,\"f_query\":1,\"f_rfi\":1,\"f_methods\":1,\"f_wpnoise\":1,\"htaccess_external\":0,\"shield_autoheal\":1,\"shield_autoheal_last\":0,\"mig_selfon_2415\":1,\"guard_dismissed\":0,\"x_shield\":1,\"x_sigs_off\":[],\"defs_version\":\"2026-07-15.9ac386\",\"mal_whitelist\":[],\"u_harden\":1,\"u_dirs\":[\"images\",\"media\"],\"emergency_lock\":0,\"notify_email\":\"pch.info@dubbelbit.nl\",\"notify_reminder_days\":14,\"unsub_secret\":\"knIOkiU01E3ceU0YZZ8ARjTQkWuTbqXAfktb1qjg6K0\",\"unsub_base\":\"https:\\/\\/www.efitec.nl\\/\",\"site_fp\":\"6d83c72d155aaa19f87ab9edd8cf222657b5b548\",\"swarm_contrib_id\":\"\",\"swarm_acked\":[],\"watch_manifest\":{\".htaccess\":\"dcb97f95087f2bdb336d0ffdcc300371ca6c4c51\",\"administrator\\/.htaccess\":\"2a00152a7d76a1d4a9444edf477c7404821a8b08\",\"images\\/.htaccess\":\"69714eb0929213f686d66baa144fceefbb395f8f\",\"media\\/.htaccess\":\"69714eb0929213f686d66baa144fceefbb395f8f\"},\"core_manifest\":{\"index.php\":\"2f1b60fc565276ae146bea9aaeadec93fb4dc87c\",\"administrator\\/index.php\":\"7078c5d7b2181900c509c93302f324e2dae228bf\"},\"core_jversion\":\"3.10.12\",\"accounts_watch\":1,\"account_baseline\":{\"613\":{\"id\":613,\"username\":\"admin\",\"email\":\"pch.info@dubbelbit.nl\",\"phash\":\"6300584d05e69c7f07ba2fb51a2f5ade41aeedd4\",\"block\":0,\"lastvisit\":\"2026-07-15 10:54:36\",\"pneeds\":0},\"800\":{\"id\":800,\"username\":\"dubbelbit\",\"email\":\"info@dubbelbit.nl\",\"phash\":\"081a5bae87c5a349a57ac9416a5157be4b8f95d5\",\"block\":0,\"lastvisit\":\"2025-11-06 17:15:16\",\"pneeds\":0}},\"admin_whitelist\":[],\"helix_ignore\":[],\"seo_watch\":1,\"compat_guard\":1,\"seo_cloaking_auto\":0,\"seo_whitelist\":[],\"seo_topic_ack\":[],\"seo_baseline\":{\"title\":\"Home\",\"out_domains\":{\"www.facebook.com\":1,\"nl.pinterest.com\":1,\"www.youtube.com\":1,\"www.s-bb.nl\":1,\"nieuw.efitec.nl\":1,\"xdebug.org\":1},\"shingles\":{\"511079512\":1,\"2918310184\":1,\"155886152\":1,\"3160688592\":1,\"3485062088\":1,\"585239104\":1,\"3828873704\":1,\"4087449296\":1,\"3631890208\":1,\"2453473432\":1,\"352088384\":1,\"1507055824\":1,\"1387258184\":1,\"96078016\":1,\"4120744744\":1,\"884599352\":1,\"148068952\":1,\"2322729328\":1,\"1647395640\":1,\"550572240\":1,\"2804985368\":1,\"2665301464\":1,\"3371643872\":1,\"1999195856\":1,\"412108984\":1,\"2599037872\":1,\"4081499304\":1,\"187337984\":1,\"362962264\":1,\"2094558736\":1,\"2787016200\":1,\"1792673952\":1,\"569970656\":1,\"3190343216\":1,\"2235320368\":1,\"4032774184\":1,\"3719766864\":1,\"148784336\":1,\"3910888496\":1,\"2105768312\":1,\"431985168\":1,\"1779663400\":1,\"3387634344\":1,\"3545206312\":1,\"1365474280\":1,\"1552018832\":1,\"344452216\":1,\"3493577104\":1,\"202494824\":1,\"2217906320\":1,\"2554787144\":1,\"2498922880\":1,\"1848356288\":1,\"3951814824\":1,\"2623166256\":1,\"730945648\":1,\"3457890904\":1,\"277629640\":1,\"982788704\":1,\"3214585776\":1,\"1332842344\":1,\"1366336928\":1,\"1310141264\":1,\"3778128584\":1,\"1993946344\":1,\"140539032\":1,\"3961562944\":1,\"2756089672\":1,\"829495128\":1,\"1139362632\":1,\"1375429072\":1,\"1759417520\":1,\"2983867360\":1,\"2737376608\":1,\"4133289600\":1,\"3352341240\":1,\"682230128\":1,\"584864880\":1,\"2799752896\":1,\"2328740824\":1,\"2901302328\":1,\"3548027512\":1,\"1490224168\":1,\"3413516768\":1,\"3696537144\":1,\"211001480\":1,\"1209613064\":1,\"1950179312\":1,\"39928272\":1,\"2520740096\":1,\"810676984\":1,\"3946537872\":1,\"1061088320\":1,\"924937024\":1,\"2981285080\":1,\"3538140264\":1,\"2706907200\":1,\"4109595712\":1,\"1158834928\":1,\"4102387360\":1,\"4061168168\":1,\"4118382176\":1,\"1925217168\":1,\"4239054088\":1,\"254204696\":1,\"2797136096\":1,\"3557110600\":1,\"4041208904\":1,\"1327249520\":1,\"1607673584\":1,\"4007425464\":1,\"2632851624\":1,\"2693581640\":1,\"2622914680\":1,\"1094268640\":1,\"1935561680\":1,\"1300147528\":1,\"3008275536\":1,\"1337666672\":1,\"2991890336\":1,\"3462925544\":1,\"2964742568\":1,\"3316732424\":1,\"1561660688\":1,\"4194141552\":1,\"1048480240\":1,\"1489547928\":1,\"1806222752\":1,\"394294200\":1,\"2776431456\":1,\"507422944\":1,\"4101744904\":1,\"1439432160\":1,\"942566752\":1,\"3196827536\":1,\"3834415704\":1,\"1559046784\":1,\"4007417480\":1,\"7730296\":1,\"1458451704\":1,\"2911589176\":1,\"454621680\":1,\"1251844592\":1,\"2438508112\":1,\"1820085032\":1,\"3409153800\":1,\"4001889160\":1,\"1048475128\":1,\"3101468488\":1,\"4123225216\":1,\"670221008\":1,\"2571777288\":1,\"3627078176\":1,\"293222816\":1,\"281163600\":1,\"2508087208\":1,\"556226104\":1,\"3114846224\":1,\"848595304\":1,\"3107900104\":1,\"2589595704\":1,\"2034508136\":1,\"1977429088\":1,\"2584638584\":1,\"2493542936\":1,\"1031407784\":1,\"2846665840\":1,\"1613823168\":1,\"39764600\":1,\"4261163824\":1,\"3543193024\":1,\"2227640984\":1,\"1856123928\":1,\"376102376\":1,\"3854411392\":1,\"2256249280\":1,\"1618392856\":1,\"3294019280\":1,\"2709313920\":1,\"444641888\":1,\"4217705304\":1,\"716719120\":1,\"4214313248\":1,\"448164984\":1,\"933003528\":1,\"2230427152\":1,\"1208455864\":1,\"2025534160\":1,\"1408784776\":1,\"2685059296\":1,\"3489792648\":1,\"1615724560\":1,\"2550915448\":1,\"650342624\":1,\"1911606592\":1,\"1198709224\":1,\"2552993816\":1,\"2123798152\":1,\"3761658400\":1,\"3237738368\":1,\"844784608\":1,\"2874506056\":1,\"4124423392\":1,\"1153004272\":1,\"796890520\":1,\"1247028480\":1,\"958748368\":1,\"1744512424\":1,\"647816080\":1,\"1123389784\":1,\"743882928\":1,\"1349587552\":1,\"109843936\":1,\"3303788176\":1,\"3393712720\":1,\"2772452800\":1,\"2879097760\":1,\"1345583752\":1,\"4138023008\":1,\"1630734352\":1,\"1587613576\":1,\"1950652592\":1,\"2777296976\":1,\"2621186584\":1,\"36106456\":1,\"2825573424\":1,\"303059736\":1,\"3664056600\":1,\"1223539912\":1,\"401106408\":1,\"335870296\":1,\"947878136\":1,\"885775072\":1,\"2836090264\":1,\"1479167544\":1,\"3195444184\":1,\"1373515616\":1,\"2703441304\":1,\"2999798000\":1,\"2744542272\":1,\"3679148440\":1,\"4128820280\":1,\"4023978944\":1,\"3226643448\":1,\"3914545768\":1,\"3485632672\":1,\"1455493656\":1,\"3040222736\":1,\"1738075592\":1,\"3987514200\":1,\"428036792\":1,\"2710735120\":1,\"3436957576\":1,\"3230827720\":1,\"1002378832\":1,\"477165832\":1,\"1378722152\":1,\"2798472384\":1,\"272556984\":1,\"1915969656\":1,\"351010464\":1,\"2168780672\":1,\"968175280\":1,\"2826036216\":1,\"420540632\":1,\"4203005848\":1,\"3687294800\":1,\"1048347112\":1,\"4015778440\":1,\"1216866856\":1,\"172199312\":1,\"1859028960\":1,\"2694091560\":1,\"2607914576\":1,\"2851112608\":1,\"2834052552\":1,\"3439897368\":1,\"2073771664\":1,\"3681309080\":1,\"2144818552\":1,\"3130333816\":1,\"3591606896\":1,\"1894249248\":1,\"4188555200\":1,\"245520800\":1,\"1682089672\":1,\"9149544\":1,\"3226699984\":1,\"1372800744\":1,\"2964205104\":1,\"722285192\":1,\"548688272\":1,\"4026953320\":1,\"1116378504\":1,\"3895415872\":1,\"1253935208\":1,\"528756504\":1,\"2284709784\":1,\"802473640\":1,\"3733678920\":1,\"361847392\":1,\"1232831160\":1,\"144058216\":1,\"1338885880\":1,\"992984272\":1,\"3773773072\":1,\"4182600\":1,\"2502992360\":1,\"4070217592\":1,\"331252280\":1,\"3604061016\":1,\"1416323816\":1,\"821879880\":1,\"3181784208\":1,\"1711020488\":1,\"1530568368\":1,\"3978930832\":1,\"4141876912\":1,\"3134899488\":1,\"1235858440\":1,\"810201200\":1,\"1254024240\":1,\"1246915864\":1,\"3515040152\":1,\"798171424\":1,\"3843014608\":1,\"610676112\":1,\"13010368\":1,\"3925377248\":1,\"3781864704\":1,\"3031336392\":1,\"3039953848\":1,\"1385104704\":1,\"4245224744\":1,\"4290332968\":1,\"2274655504\":1,\"1645581528\":1,\"2669455816\":1,\"2339052568\":1,\"411889912\":1,\"3722712864\":1,\"1646278032\":1,\"2080430464\":1,\"1286501976\":1,\"1591713568\":1,\"1088809128\":1,\"3634194248\":1,\"3235297640\":1,\"1552428824\":1,\"1872388720\":1,\"1793498072\":1,\"1067862528\":1,\"2964611496\":1,\"1211668720\":1,\"252019184\":1,\"673687856\":1,\"1020035096\":1,\"1477984416\":1,\"798794864\":1,\"3895830512\":1,\"3877253568\":1,\"3725099576\":1,\"2100351152\":1,\"2474987096\":1,\"2873487888\":1,\"395115384\":1,\"73942424\":1,\"13272208\":1,\"1943482168\":1,\"1547675656\":1,\"1718305248\":1,\"1732106904\":1,\"1643112200\":1,\"2779522920\":1,\"3059048408\":1},\"redirect_to\":\"\",\"ts\":1790373919},\"seo_overview_ts\":1790373917,\"seo_overview_finding\":[],\"core_overview_ts\":1784128054,\"core_overview_finding\":[],\"plugin_initialized\":1,\"quickicon_initialized\":1,\"autosecure\":0,\"autosecure_last\":0,\"tmp_autoclean\":0,\"tmp_keep\":[],\"autoupdate_notify\":0,\"autoupdate_ext\":1,\"autoupdate_all\":0,\"autoupdate_self\":1,\"autoupdate_manual\":0,\"autoupdate_mail_success\":0,\"autoupdate_include\":[],\"autoupdate_keep\":1,\"autoupdate_interval\":86400,\"autoupdate_schedule\":\"daily\",\"autoupdate_hour\":21,\"autoupdate_weekday\":5,\"autoupdate_grace\":3,\"autoupdate_malscan\":1,\"autoupdate_skip_major\":0,\"keep_update_sites\":1,\"keep_update_sites_except\":[],\"s_php\":1,\"s_types\":1,\"s_ext\":\"7z,avif,bmp,br,css,csv,doc,docx,eot,geojson,gif,gml,gpx,gz,htm,html,ico,ics,jp2,jpe,jpeg,jpg,js,json,kml,kmz,m4a,m4v,map,mjs,mov,mp3,mp4,mpeg,mpg,odp,ods,odt,oga,ogg,ogv,opus,otf,pdf,png,ppt,pptx,rar,rtf,svg,svgz,tif,tiff,ttf,txt,vtt,wasm,wav,webm,webmanifest,webp,woff,woff2,xls,xlsx,xml,xsl,zip\",\"s_files\":[\"administrator\\/components\\/com_akeeba\\/restore.php\",\"administrator\\/components\\/com_akeebabackup\\/restore.php\"],\"s_dirs_php\":[\"plugins\\/system\\/bfnetwork\"],\"s_dirs_static\":[],\"allow_paths\":[],\"s_dotfiles\":1,\"s_wellknown\":1,\"s_sensitive\":1,\"s_manifests\":0,\"s_sysdirs\":1,\"s_sysdirs_list\":[\"administrator\\/cache\",\"administrator\\/logs\",\"cache\",\"cli\",\"log\",\"logs\",\"tmp\"],\"p_compress\":1,\"p_precomp\":0,\"p_expires\":1,\"p_etag\":0,\"custom_top\":\"\",\"custom_bottom\":\"\",\"file_sha1\":\"dcb97f95087f2bdb336d0ffdcc300371ca6c4c51\",\"last_written\":\"2026-07-15 17:20:03\",\"last_test\":{\"checks\":[{\"label\":\"Home page reachable\",\"url\":\"https:\\/\\/www.efitec.nl\\/\",\"status\":200,\"ok\":true,\"note\":\"\"},{\"label\":\"Backend reachable (401 = password protection active)\",\"url\":\"https:\\/\\/www.efitec.nl\\/administrator\\/index.php\",\"status\":401,\"ok\":true,\"note\":\"\"},{\"label\":\"PHP shield active (test call is rejected with 403)\",\"url\":\"https:\\/\\/www.efitec.nl\\/htpx-canary-fbfbe897.php\\/htp\",\"status\":403,\"ok\":true,\"note\":\"\"},{\"label\":\"configuration.php blocked\",\"url\":\"https:\\/\\/www.efitec.nl\\/configuration.php\",\"status\":403,\"ok\":true,\"note\":\"\"}],\"regression\":false,\"reason\":\"\",\"time\":\"2026-07-15 15:20:03\"},\"guard_dir\":\"\",\"guard_recover\":\"263c210ee005a46813c42d75dd82d7144cb9b918b4356d8c60a8f9225963fe48\",\"welcome_sent\":1,\"welcome_green_since\":0,\"jed_review_ack\":\"\",\"jed_mail_last\":0,\"htaccess_cap\":[]},\"htp_defs\":{\"schema\":1,\"version\":\"2026-09-18.82d55a\",\"signatures\":[{\"id\":\"jce-profiles-import\",\"label\":\"JCE Profil-Import (CVE-2026-48907)\",\"label_en\":\"JCE profile import (CVE-2026-48907)\",\"desc\":\"Unauthentifizierter Profil-Import im JCE-Editor - Beginn der aktuellen RCE-Kette (schaltet PHP-Uploads frei). Kein legitimer Frontend-Aufruf.\",\"desc_en\":\"Unauthenticated profile import in the JCE editor - start of the current RCE chain (enables PHP uploads). No legitimate frontend call.\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*task=profiles\\\\.import)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"jce-rpc-upload\",\"label\":\"JCE Webshell-Upload via plugin.rpc (CVE-2026-48907)\",\"label_en\":\"JCE webshell upload via plugin.rpc (CVE-2026-48907)\",\"desc\":\"Datei-Upload \\u00fcber den JCE-Dateibrowser (plugin.rpc, method=upload). Greift nur im Frontend; eingeloggte Autoren (legitimer Editor-Upload) bleiben unber\\u00fchrt.\",\"desc_en\":\"File upload via the JCE file browser (plugin.rpc, method=upload). Applies only on the frontend; logged-in authors (legitimate editor upload) are unaffected.\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*task=plugin\\\\.rpc)(?=.*method=upload)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":null},{\"id\":\"jce-imgmanager\",\"label\":\"JCE Image Manager (Alt-Exploit)\",\"label_en\":\"JCE Image Manager (legacy exploit)\",\"desc\":\"Klassischer unauthentifizierter Datei-Upload \\u00fcber den JCE-Bildmanager (sehr alte JCE-Versionen).\",\"desc_en\":\"Classic unauthenticated file upload via the JCE image manager (very old JCE versions).\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*plugin=imgmanager)(?=.*method=form)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":null},{\"id\":\"novarain-nrframework\",\"label\":\"Novarain \\/ Tassos Framework (com_ajax include)\",\"label_en\":\"Novarain \\/ Tassos Framework (com_ajax include)\",\"desc\":\"CVE-2026-21627: unauthentifizierte PHP-Datei-Einbindung \\u00fcber plg_system_nrframework via com_ajax (task=include).\",\"desc_en\":\"CVE-2026-21627: unauthenticated PHP file inclusion via plg_system_nrframework through com_ajax (task=include).\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*nrframework)(?=.*task=include)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"astroid-ajax\",\"label\":\"Astroid Framework (AJAX-Endpunkt)\",\"label_en\":\"Astroid Framework (AJAX endpoint)\",\"desc\":\"CVE-2026-21628: ungepr\\u00fcfter Astroid-AJAX-Endpunkt (Upload\\/Installation). Coarse-Match auf com_ajax + astroid.\",\"desc_en\":\"CVE-2026-21628: unchecked Astroid AJAX endpoint (upload\\/installation). Coarse match on com_ajax + astroid.\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*(plugin|template|view)=astroid)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"helix3-ajax\",\"label\":\"Helix3 (JoomShaper): unauth. com_ajax-Handler (Datei schreiben\\/l\\u00f6schen)\",\"label_en\":\"Helix3 (JoomShaper): unauth com_ajax handler (file write\\/delete)\",\"desc\":\"Helix3 < 3.1.2: der Ajax-Handler onAjaxHelix3 pr\\u00fcfte weder Login noch Rechte. Trifft gezielt die gef\\u00e4hrlichen Unauth-Aktionen im POST-Body: save (Layout-JSON ins aktive Template schreiben), remove (Datei l\\u00f6schen via Path-Traversal), import (Template-Style-Settings \\u00fcberschreiben) sowie upload_image\\/remove_image\\/updateFonts. Legitime Gast-Aktionen (voting, load) und eingeloggte Template-Nutzung \",\"desc_en\":\"Helix3 < 3.1.2: the onAjaxHelix3 ajax handler checked neither login nor permission. Targets the dangerous unauth POST-body actions: save (write layout JSON into the active template), remove (delete a file via path traversal), import (overwrite template style settings) plus upload_image\\/remove_image\\/updateFonts. Legitimate guest actions (voting, load) and logged-in template use are unaffected. Fix:\",\"default\":1,\"qs\":\"data(?:\\\\[|%5b)action(?:\\\\]|%5d)=(?:save|remove|import|updatefonts)|action=(?:upload_image|remove_image)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"helix3-comajax\",\"label\":\"Helix3 (JoomShaper): unauth. com_ajax-Dispatcher (Datei-Write\\/Delete, Style-Injektion)\",\"label_en\":\"Helix3 (JoomShaper): unauth com_ajax dispatcher (file write\\/delete, style injection)\",\"desc\":\"Helix3 < 3.1.2: der Front-Dispatcher (option=com_ajax mit plugin=helix3) rief onAjaxHelix3 VOR jeder Token-\\/Rechtepr\\u00fcfung auf - unauthentifiziert save\\/import\\/remove\\/resetLayout\\/updateFonts\\/fontVariants (Datei-Schreiben, Path-Traversal-L\\u00f6schen, Template-Style-Injektion, Stored XSS). Blockt jeden GAST-Aufruf dieses Dispatchers im Frontend (Defense-in-Depth, f\\u00e4ngt auch laufende Scans) - erg\\u00e4nzt d\",\"desc_en\":\"Helix3 < 3.1.2: the front-end dispatcher (option=com_ajax with plugin=helix3) invoked onAjaxHelix3 BEFORE any token\\/permission check - unauthenticated save\\/import\\/remove\\/resetLayout\\/updateFonts\\/fontVariants (file write, path-traversal delete, template style injection, stored XSS). Blocks every GUEST call of this dispatcher on the front end (defense in depth, also catches ongoing scans) - complemen\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*plugin=helix3\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"helixultimate-comajax\",\"label\":\"Helix Ultimate (JoomShaper): unauth. com_ajax-Dispatcher (Men\\u00fc-Write\\/Datei\\/Export)\",\"label_en\":\"Helix Ultimate (JoomShaper): unauth com_ajax dispatcher (menu write\\/file\\/export)\",\"desc\":\"Helix Ultimate < 2.2.7: der com_ajax-Handler onAjaxHelixultimate (option=com_ajax mit plugin=helixultimate, Action im task-Param) lief VOR jeder Login-\\/Rechtepr\\u00fcfung - ein anonymer Angreifer konnte in die Men\\u00fc-Einstellungen schreiben (Stored XSS bis in die Admin-Sitzung), Dateien per Path-Traversal beliebig l\\u00f6schen, einen Open Redirect ausl\\u00f6sen und das Template ungesch\\u00fctzt exportieren. Blockt\",\"desc_en\":\"Helix Ultimate < 2.2.7: the com_ajax handler onAjaxHelixultimate (option=com_ajax with plugin=helixultimate, action in the task param) ran BEFORE any login\\/permission check - an anonymous attacker could write into the menu settings (stored XSS reaching the admin session), delete files anywhere via path traversal, trigger an open redirect and export the template unprotected. Blocks every GUEST call\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*plugin=helixultimate\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"comajax-include\",\"label\":\"com_ajax: Datei-Einbindung (generisch)\",\"label_en\":\"com_ajax: file inclusion (generic)\",\"desc\":\"F\\u00e4ngt unbekannte LFI-L\\u00fccken derselben Klasse ab: com_ajax mit task=include\\/require. Frontend.\",\"desc_en\":\"Catches unknown LFI holes of the same class: com_ajax with task=include\\/require. Frontend.\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*task=(include|require)(_once)?)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"sppagebuilder-uploadicon\",\"label\":\"SP Page Builder: unauthentifizierter Icon-Upload (RCE)\",\"label_en\":\"SP Page Builder: unauthenticated icon upload (RCE)\",\"desc\":\"Zero-Day in SP Page Builder bis 6.6.1: der asset-Controller (task=asset.uploadCustomIcon) hatte keinerlei Zugriffs-\\/Login-Pr\\u00fcfung - unauthentifizierter Datei-Upload nach \\/media\\/com_sppagebuilder\\/assets\\/iconfont\\/ - RCE. Nur Mini-WAF (G\\u00e4ste), da eingeloggte Builder den Endpunkt legitim nutzen.\",\"desc_en\":\"Zero-day in SP Page Builder up to 6.6.1: the asset controller (task=asset.uploadCustomIcon) had no access\\/login check - unauthenticated file upload to \\/media\\/com_sppagebuilder\\/assets\\/iconfont\\/ - RCE. Mini-WAF only (guests), since logged-in builders use the endpoint legitimately.\",\"default\":1,\"qs\":\"(?=.*option=com_sppagebuilder)(?=.*task=asset\\\\.uploadCustomIcon)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":null},{\"id\":\"dpcalendar-createdby-sqli\",\"label\":\"DPCalendar: unauth. SQL-Injection (Autor-Filter)\",\"label_en\":\"DPCalendar: unauth SQL injection (author filter)\",\"desc\":\"DPCalendar Blind-SQLi (Joomla 4.4-6 < 10.11.2, J3 < 8.19.4): der Frontend-Autor-Filter filter_created_by (option=com_dpcalendar, view=events) floss in skalarer Form ungecastet in a.created_by IN (...) - anonymes Auslesen beliebiger DB-Tabellen (nur lesend). Blockt Gast-Anfragen, deren filter_created_by kein reiner Integer ist (legitim = Autor-IDs\\/Ziffern) -> FP-frei. Fix 10.11.2 \\/ 8.19.4.\",\"desc_en\":\"DPCalendar blind SQLi (Joomla 4.4-6 < 10.11.2, J3 < 8.19.4): the front-end author filter filter_created_by (option=com_dpcalendar, view=events) flowed uncast into a.created_by IN (...) in its scalar form - anonymous read of arbitrary DB tables (read-only). Blocks guest requests whose filter_created_by is not a pure integer (legit = author IDs\\/digits) -> FP-free. Fix 10.11.2 \\/ 8.19.4.\",\"default\":1,\"qs\":\"(?=.*option=com_dpcalendar)(?=.*filter_created_by=[0-9,]*[^0-9,&])\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_dpcalendar\"},{\"id\":\"acym-entityselect-sqli\",\"label\":\"AcyMailing: unauth. SQL-Injection (Entity-Select Spaltenliste)\",\"label_en\":\"AcyMailing: unauth SQL injection (entity-select column list)\",\"desc\":\"CVE-2026-56292 (AcyMailing 6.0.0-10.11.0): der Frontend-Endpunkt EntitySelectController::loadEntityFront (option=com_acym, task=loadEntityFront) nahm die Request-Parameter columns\\/join_table ungeprueft in die SELECT-Spaltenliste von UserClass::getMatchingElements auf - ein anonymer Besucher konnte per Subquery beliebige DB-Tabellen (inkl. Passwort-Hashes) auslesen. Blockt GAST-Aufrufe dieses Tasks\",\"desc_en\":\"CVE-2026-56292 (AcyMailing 6.0.0-10.11.0): the front-end endpoint EntitySelectController::loadEntityFront (option=com_acym, task=loadEntityFront) placed the request parameters columns\\/join_table unchecked into the SELECT column list of UserClass::getMatchingElements - an anonymous visitor could read arbitrary DB tables (incl. password hashes) via a subquery. Blocks GUEST calls of this task whose c\",\"default\":1,\"qs\":\"(?=.*option=com_acym)(?=.*task=loadEntityFront)(?=.*(?:columns|join_table|join)=[^&]*(?:\\\\(|%28|%2528|\\\\s|%20|\\\\+))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_acym\"},{\"id\":\"quix-article-sqli\",\"label\":\"Quix Page Builder: unauth. SQL-Injection (Einzel-Artikel-AJAX)\",\"label_en\":\"Quix Page Builder: unauth SQL injection (single-article AJAX)\",\"desc\":\"Quix (ThemeXpert, Free UND Pro) bis 6.2.0, inkl. der 5.x-Reihe: der oeffentliche AJAX-Endpunkt (option=com_quix, task=ajax, element=joomla-article) ruft QuixJoomlaArticleElement::getAjax() ohne Login-\\/Token-\\/Lizenz-Pruefung; die Artikel-ID kommt base64-kodiert im data-Parameter und wird in articleExist() UNGECASTET in die DB-Query konkateniert -> unauthentifizierte, fehler-basierte SQL-Injection (\",\"desc_en\":\"Quix (ThemeXpert, Free AND Pro) up to 6.2.0, incl. the 5.x line: the public AJAX endpoint (option=com_quix, task=ajax, element=joomla-article) calls QuixJoomlaArticleElement::getAjax() with no login\\/token\\/license check; the article id arrives base64-encoded in the data parameter and is concatenated UNCAST into the DB query in articleExist() -> unauthenticated error-based SQL injection (CVSS 8.7). \",\"default\":1,\"qs\":\"(?=.*option=com_quix)(?=.*task=ajax\\\\b)(?=.*element=joomla-article\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_quix\"},{\"id\":\"phocacart-filter-sqli\",\"label\":\"Phoca Cart: unauth. SQL-Injection (Produktfilter a\\/s)\",\"label_en\":\"Phoca Cart: unauth SQL injection (product filter a\\/s)\",\"desc\":\"CVE-2026-74251 (CVSS 9.3, Phoca Cart J5-Reihe < 5.2.4 \\/ J6-Reihe < 6.1.7; 3.x und 4.x komplett): der \\u00f6ffentliche Produktfilter (option=com_phocacart) liest die Array-Parameter a (Attribute) und s (Spezifikationen) und h\\u00e4ngt ihre Werte UNGEQUOTET in die WHERE-Klausel (IN()- bzw. Gleichheits-Bedingung) - auf einer Gast-Seite ohne Login\\/Token -> unauthentifizierte, blinde SQL-Injection (Auslesen de\",\"desc_en\":\"CVE-2026-74251 (CVSS 9.3, Phoca Cart J5 line < 5.2.4 \\/ J6 line < 6.1.7; 3.x and 4.x entirely): the public product filter (option=com_phocacart) reads the array parameters a (attributes) and s (specifications) and appends their values UNQUOTED into the WHERE clause (IN() \\/ equality condition) - on a guest page with no login\\/token -> unauthenticated blind SQL injection (database read). Blocks GUEST \",\"default\":1,\"qs\":\"(?=(?:^|.*&)option=com_phocacart)(?=(?:^|.*&)(?:%20|\\\\+|\\\\s)*(?:a|s)(?:\\\\[|%5b)[^&]*(?:%(?:27|22|5c)|[\\\\x27\\\\x22\\\\x5c]))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_phocacart\"},{\"id\":\"icagenda-calendar-sqli\",\"label\":\"iCagenda: unauth. SQL-Injection (Kalender-Modul \\u00fcber com_ajax)\",\"label_en\":\"iCagenda: unauth SQL injection (calendar module via com_ajax)\",\"desc\":\"CVE-2026-67365 (CVSS 9.2, iCagenda 4.0.0-4.0.11): das Kalender-Modul mod_icagenda_calendar wird \\u00fcber com_ajax (option=com_ajax&module=icagenda_calendar) OHNE Session, Token oder Konto erreicht und haengt einen Request-Parameter ungefiltert in eine SQL-Abfrage - unauthentifizierte SQL-Injection (Datenbank auslesen). Das Kalender-Ajax ist ein LEGITIMES Gast-Feature (Monats-\\/Kategorie-Navigation), d\",\"desc_en\":\"CVE-2026-67365 (CVSS 9.2, iCagenda 4.0.0-4.0.11): the calendar module mod_icagenda_calendar is reached via com_ajax (option=com_ajax&module=icagenda_calendar) with NO session, token or account and appends a request parameter unfiltered into a SQL query - unauthenticated SQL injection (database read). The calendar ajax is a LEGITIMATE guest feature (month\\/category navigation), so this does NOT bloc\",\"default\":1,\"qs\":\"(?=(?:^|.*&)option=com_ajax)(?=(?:^|.*&)module=icagenda_calendar)(?=.*(?:%27|%22|%5c|[\\\\x27\\\\x22\\\\x5c]|\\\\bunion\\\\b[\\\\s+\\/*]*\\\\bselect\\\\b|information_schema|(?:sleep|benchmark|extractvalue|updatexml)(?:%28|\\\\()))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"joomcck-tags-sqli\",\"label\":\"JoomCCK: unauth. SQL-Injection (Tag-Verwaltung)\",\"label_en\":\"JoomCCK: unauth SQL injection (tag management)\",\"desc\":\"CVE-2026-49048 (JoomCCK 6.x vor 6.4.1): der Front-End-Task tags.save\\/tags.delete (option=com_joomcck) lief OHNE Token-\\/Login-\\/Rechte-Pruefung und schob den Request-Parameter tag (getString) roh - mit Double-Quote-Ausbruch - in ZWEI aufeinanderfolgende SQL-Statements (Existenz-SELECT + UPDATE). Ein anonymer Besucher konnte die Datenbank auslesen und veraendern (stacked\\/error-based SQLi). Blockt jed\",\"desc_en\":\"CVE-2026-49048 (JoomCCK 6.x before 6.4.1): the front-end task tags.save\\/tags.delete (option=com_joomcck) ran with NO token\\/login\\/permission check and concatenated the request parameter tag (getString) raw - with a double-quote breakout - into TWO consecutive SQL statements (existence SELECT + UPDATE). An anonymous visitor could read and modify the database (stacked\\/error-based SQLi). Blocks every \",\"default\":1,\"qs\":\"(?=.*option=com_joomcck)(?=.*task=tags\\\\.(?:save|delete))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_joomcck\"},{\"id\":\"gridbox-store-register\",\"label\":\"Balbooa Gridbox: unauth. Konto-Erstellung (store.register)\",\"label_en\":\"Balbooa Gridbox: unauth account creation (store.register)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, gemeldet 2026-07-28, Fix in 2.20.2 (29.07.2026). Der Front-End-Task store.register lief OHNE Login\\/Token und legte ein Joomla-Konto mit FREI WAEHLBARER Usergruppe plus sofort gueltiger Session an (unauth Privilege Escalation). Blockt jeden Gast-Aufruf dieses Tasks. Kosten: falls die Site die Gridbox-eigene Frontend-Registrierung nu\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to and incl. 2.20.1 - actively exploited, reported 2026-07-28, fixed in 2.20.2 (29 Jul 2026). The front-end task store.register ran WITHOUT login\\/token and created a Joomla account with an ARBITRARY usergroup plus an immediately valid session (unauth privilege escalation). Blocks every guest call of this task. Cost: if the site uses Gridbox front-end registration (\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=store(\\\\.|%2e)register)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":\"com_gridbox\"},{\"id\":\"gridbox-uploader-showimage-read\",\"label\":\"Balbooa Gridbox: unauth. Datei-Lesen (uploader.showImage)\",\"label_en\":\"Balbooa Gridbox: unauth arbitrary file read (uploader.showImage)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, Fix in 2.20.2 (29.07.2026). Der Front-End-Task uploader.showImage laed ohne Login den Query-Parameter image= und gibt bei Nicht-Bildern die Datei roh aus (fopen+fpassthru) -> unauth Arbitrary File Read, u. a. configuration.php. Trifft JEDE Gridbox-Installation. FP-FREI (2.6.17, Fall prolocore-vigezzo.it: Gridbox laed Bilder als abs\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to and incl. 2.20.1 - actively exploited, fixed in 2.20.2 (29 Jul 2026). The front-end task uploader.showImage reads the query parameter image= without login and, for non-images, dumps the file raw (fopen+fpassthru) -> unauth arbitrary file read incl. configuration.php. Hits EVERY Gridbox install. FP-FREE (2.6.17, case prolocore-vigezzo.it: Gridbox references image\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=uploader(\\\\.|%2e)showImage)(?=.*image=(?:[^&]*(?:\\\\.\\\\.|%2e%2e|%00|php:|php%3a)|(?![^&]*\\\\.(?:jpe?g|png|gif|webp|svg|bmp|ico|avif|tiff?)(?:[&?]|%3f|$))[^&]+))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":\"com_gridbox\"},{\"id\":\"gridbox-uploader-savephoto\",\"label\":\"Balbooa Gridbox: unauth. Datei-Schreiben (uploader.savePhotoEditorImage)\",\"label_en\":\"Balbooa Gridbox: unauth arbitrary file write (uploader.savePhotoEditorImage)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, Fix in 2.20.2 (29.07.2026). Der Front-End-Task uploader.savePhotoEditorImage schreibt eine beliebige Datei (inkl. .php) in den Webroot; der Zieldateiname liegt im POST-Body (php:\\/\\/input) und ist fuer die .htaccess unsichtbar, und eingeloggte Redakteure nutzen den Endpunkt legitim. Daher waf_only + scope=guest: NUR im Echtzeit-Plugi\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to and incl. 2.20.1 - actively exploited, fixed in 2.20.2 (29 Jul 2026). The front-end task uploader.savePhotoEditorImage writes an arbitrary file (incl. .php) into the webroot; the target filename is in the POST body (php:\\/\\/input), invisible to .htaccess, and logged-in editors use the endpoint legitimately. Hence waf_only + scope=guest: enforced ONLY in the real-t\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=uploader(\\\\.|%2e)savePhotoEditorImage)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_gridbox\"},{\"id\":\"baforms-signature-rce\",\"label\":\"Balbooa Forms: unauth. RCE (Signature-Feld, CVE-2026-65880)\",\"label_en\":\"Balbooa Forms: unauth RCE (signature field, CVE-2026-65880)\",\"desc\":\"Balbooa Forms (com_baforms) bis inkl. 2.4.2.1 - CVE-2026-65880 (CVSS 10.0), aktiv ausgenutzt, Fix erst 2.4.3. Beim Absenden eines Formulars mit SIGNATURE-Feld (task=form.sendMessage) verwendet FormModel::saveSignature den vom Angreifer im Feld-JSON gelieferten Funktionsnamen dynamisch als aufgerufene Funktion mit angeh\\u00e4ngtem Wert - unauthentifizierte Remote Code Execution. Der legitime Wert ist i\",\"desc_en\":\"Balbooa Forms (com_baforms) up to and incl. 2.4.2.1 - CVE-2026-65880 (CVSS 10.0), actively exploited, fixed only in 2.4.3. Submitting a form with a SIGNATURE field (task=form.sendMessage) makes FormModel::saveSignature use the attacker-supplied function name from the field JSON dynamically as the called function with an appended value - unauthenticated remote code execution. The legitimate value i\",\"default\":1,\"qs\":\"(?=.*\\\\bmethod[^a-z0-9]{1,6}(?:system|exec|shell_exec|passthru|assert|popen|proc_open|pcntl_exec|file_get_contents|readfile|show_source|highlight_file|fopen|scandir|phpinfo|eval|create_function|call_user_func)\\\\b)(?=.*\\\\bimage\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":1,\"trigger\":\"com_baforms\"},{\"id\":\"fabrik-calc-rce\",\"label\":\"Fabrik: unauth. RCE (calc-Element ajax_calc, CVE-2026-66915)\",\"label_en\":\"Fabrik: unauth RCE (calc element ajax_calc, CVE-2026-66915)\",\"desc\":\"Fabrik (com_fabrik) 1.0.0 bis 4.6.6 - CVE-2026-66915 (CVSS 10.0), unauthentifizierte Remote Code Execution. Der oeffentliche AJAX-Endpunkt des calc-Elements (option=com_fabrik, plugin=calc, method=ajax_calc) baut die admin-hinterlegte Rechenformel per parseMessageForPlaceHolder mit ROHEN Request-Werten ($_REQUEST) zusammen und fuehrt sie ueber die @eval-Funktion aus - ein Angreifer schleust ueber \",\"desc_en\":\"Fabrik (com_fabrik) 1.0.0 to 4.6.6 - CVE-2026-66915 (CVSS 10.0), unauthenticated remote code execution. The public AJAX endpoint of the calc element (option=com_fabrik, plugin=calc, method=ajax_calc) assembles the admin-stored calculation formula via parseMessageForPlaceHolder using RAW request values ($_REQUEST) and runs it through the @eval function - an attacker injects PHP code into the formul\",\"default\":1,\"qs\":\"(?=.*option=com_fabrik)(?=.*plugin=calc)(?=.*(?:system|exec|shell_exec|passthru|assert|popen|proc_open|pcntl_exec|file_get_contents|readfile|show_source|highlight_file|fopen|scandir|phpinfo|eval|create_function|call_user_func)\\\\s{0,3}\\\\(\\\\s{0,3}[\\\\x27\\\\x22\\\\x60$])\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":1,\"trigger\":\"com_fabrik\"},{\"id\":\"baforms-eval-rce\",\"label\":\"Balbooa Forms: unauth. RCE (eval via Query-Parameter, CVE-2026-67364)\",\"label_en\":\"Balbooa Forms: unauth RCE (eval via query parameter, CVE-2026-67364)\",\"desc\":\"Balbooa Forms (com_baforms) bis inkl. 2.4.3.1 - CVE-2026-67364 (CVSS 10.0), unauthentifizierte Remote Code Execution. Ein Formular mit eigenem PHP-Nachbearbeitungs-Handler und dem Shortcode [URL parameter=X] setzt den ROHEN, ungefilterten Query-Parameter X in den per eval-Funktion ausgefuehrten PHP-Code ein - ein Angreifer schleust darueber beliebigen PHP-Code ein (der CSRF-Token schuetzt kaum, da\",\"desc_en\":\"Balbooa Forms (com_baforms) up to and incl. 2.4.3.1 - CVE-2026-67364 (CVSS 10.0), unauthenticated remote code execution. A form with a custom PHP post-processing handler and the [URL parameter=X] shortcode substitutes the RAW, unfiltered query parameter X into the PHP code run via the eval function - an attacker injects arbitrary PHP through it (the CSRF token barely protects, being anonymously re\",\"default\":1,\"qs\":\"(?=.*option=com_baforms)(?=.*(?:system|exec|shell_exec|passthru|assert|popen|proc_open|pcntl_exec|file_get_contents|readfile|show_source|highlight_file|fopen|scandir|phpinfo|eval|create_function|call_user_func)\\\\s{0,3}\\\\(\\\\s{0,3}[\\\\x27\\\\x22\\\\x60$])\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":1,\"trigger\":\"com_baforms\"},{\"id\":\"jbusinessdirectory-upload-remove\",\"label\":\"J-Business Directory: unauth. Datei-L\\u00f6schung (upload.remove, CVE-2026-75949)\",\"label_en\":\"J-Business Directory: unauth file deletion (upload.remove, CVE-2026-75949)\",\"desc\":\"J-Business Directory (com_jbusinessdirectory) bis inkl. 6.2.2 - CVE-2026-75949 (CVSS 9.1). Der ohne Login erreichbare Task upload.remove nimmt den _filename-Parameter RAW und erzwingt keine Pfad-Eingrenzung -> ein Angreifer loescht ueber ..\\/-Sequenzen (mit _path_type=2) beliebige Dateien, u. a. configuration.php. SURGICAL: greift NUR, wenn _filename ein Traversal-\\/Nullbyte-Muster enthaelt -> norma\",\"desc_en\":\"J-Business Directory (com_jbusinessdirectory) up to and incl. 6.2.2 - CVE-2026-75949 (CVSS 9.1). The login-free task upload.remove takes the _filename parameter RAW and does not enforce path containment -> an attacker deletes arbitrary files via ..\\/ sequences (with _path_type=2), including configuration.php. SURGICAL: fires ONLY when _filename contains a traversal\\/null-byte pattern -> normal file \",\"default\":1,\"qs\":\"(?=(?:^|.*&)option=com_jbusinessdirectory)(?=.*task=upload(\\\\.|%2e)remove)(?=.*_filename[^&]*(?:\\\\.\\\\.|%2e%2e|%252e|%00))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":\"com_jbusinessdirectory\"},{\"id\":\"cottoncloud-cotton\",\"label\":\"Cotton Cloud: unauth. Dateizugriff (com_cotton)\",\"label_en\":\"Cotton Cloud: unauth file access (com_cotton)\",\"desc\":\"CVE-2026-67283 (Cotton Cloud < 2.0.3, CVSS 6.9): die Frontend-Tasks des Datei-Managers com_cotton waren nur per CSRF-Token gesch\\u00fctzt (das Joomla auch nicht eingeloggten Besuchern ausstellt) - ein anonymer Angreifer konnte Dateien lesen, l\\u00f6schen, \\u00fcberschreiben und Rechte \\u00e4ndern. Cotton Cloud gibt jedem Nutzer ein PRIVATES, kontobasiertes Cloud-Laufwerk - es gibt keinen legitimen Gast-Zugriff, d\",\"desc_en\":\"CVE-2026-67283 (Cotton Cloud < 2.0.3, CVSS 6.9): the front-end tasks of the com_cotton file manager were protected by a CSRF token only (which Joomla also issues to visitors who never logged in) - an anonymous attacker could read, delete, overwrite and re-permission files. Cotton Cloud gives every user a PRIVATE, account-based cloud drive - there is no legitimate guest access, so this signature bl\",\"default\":1,\"qs\":\"(?=(?:^|.*&)option=com_cotton\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_cotton\"},{\"id\":\"cottoncloud-shuttle\",\"label\":\"Cotton Cloud: unauth. Terminal-Zugriff (com_shuttle)\",\"label_en\":\"Cotton Cloud: unauth terminal access (com_shuttle)\",\"desc\":\"CVE-2026-67283 (Cotton Cloud < 2.0.3): beide Einstiegspunkte der Terminal-Komponente com_shuttle waren nur per CSRF-Token gesch\\u00fctzt und damit anonym erreichbar. Ein Terminal ist nie gastseitig - diese Signatur blockt jeden GAST-Aufruf von option=com_shuttle im Frontend (kein Payload-Matching, FP-frei; eingeloggte Nutzer nicht betroffen, option an eine echte Query-Grenze gebunden). Fix: Cotton Clo\",\"desc_en\":\"CVE-2026-67283 (Cotton Cloud < 2.0.3): both entry points of the com_shuttle terminal component were protected by a CSRF token only and thus reachable anonymously. A terminal is never guest-facing - this signature blocks every GUEST call of option=com_shuttle on the front end (no payload matching, FP-free; logged-in users not affected, option bound to a real query boundary). Fix: Cotton Cloud 2.0.3\",\"default\":1,\"qs\":\"(?=(?:^|.*&)option=com_shuttle\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_shuttle\"},{\"id\":\"sourcerer-reflected-php\",\"label\":\"Sourcerer (Regular Labs): unauth. RCE (reflektierter {source}-PHP-Code)\",\"label_en\":\"Sourcerer (Regular Labs): unauth RCE (reflected {source} PHP code)\",\"desc\":\"CVE-2026-74253 (CVSS 10.0, Sourcerer 1.0.0-15.0.0): Sourcerer ist ein System-Plugin, das gerenderte Inhalte nach seinem Tag {source} durchsucht und darin enthaltenen Code ausf\\u00fchrt. Bis einschlie\\u00dflich 15.0.0 fehlte eine zuverl\\u00e4ssige Herkunftspr\\u00fcfung - reflektierter oder unbest\\u00e4tigter {source}-PHP-Code (z. B. aus einem in die Seite gespiegelten Request-Parameter) wurde serverseitig ausgef\\u00fchrt:\",\"desc_en\":\"CVE-2026-74253 (CVSS 10.0, Sourcerer 1.0.0-15.0.0): Sourcerer is a system plugin that scans rendered output for its {source} tag and executes the code inside. Up to and including 15.0.0 it lacked a reliable origin check - reflected or unverified {source} PHP code (e.g. from a request parameter reflected into the page) was executed on the server: unauthenticated RCE. As there is no component anchor\",\"default\":1,\"qs\":\"(?=.*(?:\\\\x7bsource|%7[bB]source))(?=.*(?:<\\\\?(?:php|=)|%3[cC](?:%3[fF]|\\\\?)(?:php|=)))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"source\"},{\"id\":\"spproperty-search-sqli\",\"label\":\"SP Property: unauth. SQL-Injection (Immobiliensuche\\/Karte)\",\"label_en\":\"SP Property: unauth SQL injection (property search\\/map)\",\"desc\":\"CVE-2026-78082 (CVSS 9.3, SP Property von JoomShaper vor 4.1.4): Die \\u00f6ffentliche Immobiliensuche und der Kartenfilter (option=com_spproperty) verketten die Parameter zipcode, sorting, price_range_dropdown und psize_range_dropdown ROH in WHERE- und ORDER-BY-Klauseln - ohne Quoting, ohne Typumwandlung, ohne Login und ohne Token -> blinde SQL-Injektion (boolesch und zeitbasiert). Diese Signatur arbe\",\"desc_en\":\"CVE-2026-78082 (CVSS 9.3, JoomShaper SP Property before 4.1.4): the public property search and map filter (option=com_spproperty) concatenate the parameters zipcode, sorting, price_range_dropdown and psize_range_dropdown RAW into WHERE and ORDER BY clauses - no quoting, no type casting, no login, no token -> blind SQL injection (boolean and time based). This signature uses an ALLOW list of the val\",\"default\":1,\"qs\":\"(?=(?:^|.*&)option=com_spproperty)(?=(?:^|.*&)(?:(?:price|psize)_range_dropdown=[-0-9.,]*[^-0-9.,&]|sorting=[-0-9A-Za-z_. +]*[^-0-9A-Za-z_. +&]|zipcode=[-0-9A-Za-z_. +%\\\\x80-\\\\xff]*[^-0-9A-Za-z_. +%\\\\x80-\\\\xff&]))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_spproperty\"},{\"id\":\"spproperty-search-sqli-words\",\"label\":\"SP Property: unauth. SQL-Injection (Schl\\u00fcsselwort ohne Sonderzeichen)\",\"label_en\":\"SP Property: unauth SQL injection (keyword without special chars)\",\"desc\":\"Zweite H\\u00e4lfte des Schutzes f\\u00fcr CVE-2026-78082. Die Wertform-Regel spproperty-search-sqli l\\u00e4sst eine Nutzlast durch, die AUSSCHLIESSLICH aus Buchstaben, Ziffern und Leerzeichen besteht - etwa 1 union select 1 oder 1 or password like 0x6125 - weil Leerzeichen bei zipcode (Postleitzahlen wie SW1A 1AA, Ortsnamen) und bei sorting (a.price desc) legitim sind. Diese Regel schlie\\u00dft genau das: Sie bloc\",\"desc_en\":\"Second half of the protection for CVE-2026-78082. The value-shape rule spproperty-search-sqli lets through a payload made ONLY of letters, digits and spaces - such as 1 union select 1 or 1 or password like 0x6125 - because spaces are legitimate in zipcode (postal codes such as SW1A 1AA, place names) and in sorting (a.price desc). This rule closes exactly that: it blocks a guest call to com_spprope\",\"default\":1,\"qs\":\"(?=(?:^|.*&)option=com_spproperty)(?=(?:^|.*&)(?:zipcode|sorting)=[^&]*(?:[ +]|%20)(?:union|select|sleep|benchmark|like|regexp|rlike|concat|substr|extractvalue|updatexml|having|xor)\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_spproperty\"},{\"id\":\"joodb-cid-sqli\",\"label\":\"JooDatabase: unauth. SQL-Injection (Katalog-Auswahl cid)\",\"label_en\":\"JooDatabase: unauth SQL injection (catalog selection cid)\",\"desc\":\"CVE-2026-78080 (CVSS 9.3, JooDatabase\\/JooDB von feenders.de, Joomla-4\\/5\\/6-Reihe vor 5.1): Der oeffentliche Katalog (option=com_joodb) liest die Auswahl-Kennung cid und haengt jeden Wert UNGEQUOTET in die WHERE-Bedingung der Abfrage - auf einer Gast-Seite ohne Login und ohne Token. Weil der Wert im ZAHLEN-Kontext steht, braucht ein Angreifer nicht einmal ein Anfuehrungszeichen: unauthentifizierte S\",\"desc_en\":\"CVE-2026-78080 (CVSS 9.3, JooDatabase\\/JooDB by feenders.de, Joomla 4\\/5\\/6 line before 5.1): the public catalog (option=com_joodb) reads the selection identifier cid and appends every value UNQUOTED into the WHERE clause of the query - on a guest page with no login and no token. As the value sits in a NUMERIC context, an attacker does not even need a quote: unauthenticated SQL injection (database re\",\"default\":1,\"qs\":\"(?=(?:^|.*&)option=com_joodb)(?=(?:^|.*&)cid(?:(?:\\\\[|%5b|\\\\.)[^&=]*)?=[A-Za-z0-9_.\\\\-]*[^A-Za-z0-9_.\\\\-&])\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_joodb\"},{\"id\":\"traversal-encoded\",\"label\":\"Pfad-Klettern (kodierte Varianten)\",\"label_en\":\"Path traversal (encoded variants)\",\"desc\":\"Erg\\u00e4nzt den Standard-Filter um Umgehungstricks: ....\\/\\/ , doppelte Kodierung (%252e), %c0%ae, %2e%2e%5c.\",\"desc_en\":\"Extends the standard filter with bypass tricks: ....\\/\\/ , double encoding (%252e), %c0%ae, %2e%2e%5c.\",\"default\":1,\"qs\":\"(\\\\.{3,}\\/|%252e|%c0%a[ef]|%2e%2e%5c|\\\\.\\\\.%5c)\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"php-wrapper-uri\",\"label\":\"PHP-Stream-Wrapper im Pfad\",\"label_en\":\"PHP stream wrapper in the path\",\"desc\":\"Blockiert php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ , expect:\\/\\/ u. a. direkt im angefragten Pfad.\",\"desc_en\":\"Blocks php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ , expect:\\/\\/ etc. directly in the requested path.\",\"default\":1,\"qs\":null,\"uri\":\"(?:php|phar|data|expect|glob|zlib|zip):\\/\",\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"api-config-leak\",\"label\":\"Joomla-API Konfigurations-Leak\",\"label_en\":\"Joomla API configuration leak\",\"desc\":\"CVE-2023-23752: sch\\u00fctzt den Endpunkt \\/api\\/...\\/v1\\/config\\/application auch ohne komplette API-Sperre.\",\"desc_en\":\"CVE-2023-23752: protects the \\/api\\/...\\/v1\\/config\\/application endpoint even without a complete API block.\",\"default\":1,\"qs\":null,\"uri\":\"^api\\/index\\\\.php\\/v[0-9]+\\/config\",\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"php-object-injection\",\"label\":\"PHP Object Injection (serialisierte Payload)\",\"label_en\":\"PHP object injection (serialised payload)\",\"desc\":\"Serialisiertes PHP-Objekt in einem Parameter (O:\\/C:<L\\u00e4nge>:) - typischer Einstieg f\\u00fcr Object-Injection\\/POP-Ketten. Kommt in normalen Anfragen nicht vor.\",\"desc_en\":\"Serialised PHP object in a parameter (O:\\/C:<length>:) - typical entry point for object injection\\/POP chains. Does not occur in normal requests.\",\"default\":1,\"qs\":\"(?<![a-z0-9])[oc]:[0-9]{1,4}:\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"stream-wrapper-param\",\"label\":\"PHP-Stream-Wrapper in Parameter\",\"label_en\":\"PHP stream wrapper in a parameter\",\"desc\":\"php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ u. a. als Parameterwert - LFI\\/RCE-Vektor. Erg\\u00e4nzt die Pfad-Variante (php-wrapper-uri).\",\"desc_en\":\"php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ etc. as a parameter value - LFI\\/RCE vector. Complements the path variant (php-wrapper-uri).\",\"default\":1,\"qs\":\"(php|phar|data|expect|glob|zlib|zip):\\/{2}\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"param-traversal\",\"label\":\"Pfad-Klettern im Parameter\",\"label_en\":\"Path traversal in a parameter\",\"desc\":\"Mehrfaches ..\\/ als Parameterwert - generisches Directory-Traversal\\/LFI in beliebigen Komponenten.\",\"desc_en\":\"Repeated ..\\/ as a parameter value - generic directory traversal\\/LFI in any component.\",\"default\":1,\"qs\":\"=(\\\\.\\\\.\\/){2,}\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null}],\"vuln_extensions\":[{\"element\":\"aimycaptchalessformguard\",\"type\":\"plugin\",\"folder\":\"captcha\",\"name\":\"Aimy Captcha-Less Form Guard\",\"below\":\"20.1\",\"above\":\"17.0\",\"severity\":\"high\",\"note\":\"Sicherheitsl\\u00fccke in 18.0 bis 20.0, vom Hersteller in 20.1 behoben (freie und PRO-Edition betroffen). Kein Workaround - auf Aimy Captcha-Less Form Guard 20.1 oder neuer aktualisieren.\",\"note_en\":\"Security issue in 18.0 to 20.0, fixed by the vendor in 20.1 (free and PRO edition affected). No workaround - update to Aimy Captcha-Less Form Guard 20.1 or newer.\",\"advisory\":\"https:\\/\\/www.aimy-extensions.com\\/joomla\\/captcha-less-form-guard.html\",\"advisory_en\":\"https:\\/\\/www.aimy-extensions.com\\/joomla\\/captcha-less-form-guard.html\"},{\"element\":\"com_easystore\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EasyStore (JoomShaper)\",\"below\":\"2.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere unauthentifizierte SQL-Injections (CVE-2026-65759 ff.). Auf EasyStore 2.0.2 oder neuer aktualisieren.\",\"note_en\":\"Multiple unauthenticated SQL injections (CVE-2026-65759 ff.). Update to EasyStore 2.0.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65759\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65759\"},{\"element\":\"com_fabrik\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Fabrik\",\"below\":\"4.7.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische unauth. L\\u00fccken bis 4.7.1: RCE \\u00fcber calc-, PHP-Form- und Bild-Element (CVE-2026-66915\\/76604\\/76605, CVSS 10.0), dazu SQLi, Path-Traversal und ACL-Bypass. HTProtect blockt nur die calc-RCE per WAF - auf Fabrik 4.7.2 aktualisieren (schlie\\u00dft alle L\\u00fccken).\",\"note_en\":\"Multiple critical unauth. flaws up to 4.7.1: RCE via calc, PHP form and image elements (CVE-2026-66915\\/76604\\/76605, CVSS 10.0), plus SQL injection, path traversal and ACL bypass. HTProtect blocks only the calc RCE via WAF - update to Fabrik 4.7.2 (fixes all).\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-66915\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-66915\"},{\"element\":\"com_cotton\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Cotton Cloud\",\"below\":\"2.0.3\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-67283 + CVE-2026-67284 (CVSS 6.9): anonyme Besucher konnten Dateien lesen und l\\u00f6schen. HTProtect sperrt den Zugriff bereits per WAF. Auf Cotton Cloud 2.0.3 aktualisieren (2.0.2 reicht nicht).\",\"note_en\":\"CVE-2026-67283 + CVE-2026-67284 (CVSS 6.9): anonymous visitors could read and delete files. HTProtect already blocks the access via the WAF. Update to Cotton Cloud 2.0.3 (2.0.2 is not enough).\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-67283\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-67283\"},{\"element\":\"com_phocacart\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Cart\",\"below\":\"5.2.4\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-74251 (CVSS 9.3): unauthentifizierte SQL-Injection \\u00fcber den Produktfilter (a\\/s). HTProtect blockt g\\u00e4ngige Angriffe per WAF; voller Schutz erst mit Update auf Phoca Cart 5.2.4 bzw. 6.1.7.\",\"note_en\":\"CVE-2026-74251 (CVSS 9.3): unauthenticated SQL injection via the product filter (a\\/s). HTProtect blocks common attacks via the WAF; full protection only after updating Phoca Cart to 5.2.4 or 6.1.7.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-74251\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-74251\"},{\"element\":\"com_phocacart\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Cart\",\"below\":\"6.1.8\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"CVE-2026-74251 (CVSS 9.3): unauthentifizierte SQL-Injection \\u00fcber den Produktfilter (a\\/s) - HTProtect blockt g\\u00e4ngige Angriffe per WAF. Zus\\u00e4tzlich Stored-\\/Reflected-XSS (bis 6.1.7). Voller Schutz erst mit Update auf Phoca Cart 6.1.8 oder neuer.\",\"note_en\":\"CVE-2026-74251 (CVSS 9.3): unauthenticated SQL injection via the product filter (a\\/s) - HTProtect blocks common attacks via the WAF. Additionally stored\\/reflected XSS (up to 6.1.7). Full protection only after updating Phoca Cart to 6.1.8 or newer.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-74251\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-74251\"},{\"element\":\"com_splms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP LMS (JoomShaper)\",\"below\":\"4.1.4\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-48909: unauth. Code-Ausf\\u00fchrung durch unsichere Cookie-Deserialisierung. Auf SP LMS 4.1.4 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48909: unauthenticated code execution via insecure cookie deserialization. Update to SP LMS 4.1.4 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-48909\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-48909\"},{\"element\":\"com_osmembership\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Membership Pro (JoomDonation)\",\"below\":\"4.6.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-62415: kritische L\\u00fccke durch unsichere Standardkonfiguration. Auf Membership Pro 4.6.2 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-62415: critical flaw caused by an insecure default configuration. Update to Membership Pro 4.6.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-62415\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-62415\"},{\"element\":\"com_convertforms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Convert Forms (Tassos)\",\"below\":\"5.2.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische L\\u00fccken bis 5.2.2 (Datei-L\\u00f6schung, Datenleck; CVE-2024-40744); bis 5.2.4 zudem eine fehlende Zugriffskontrolle - Nicht-Angemeldete konnten Formular-Eintr\\u00e4ge auslesen (CVE-2026-77026). Update auf Convert Forms 5.2.5.\",\"note_en\":\"Multiple critical flaws up to 5.2.2 (arbitrary file deletion, data exposure; CVE-2024-40744); up to 5.2.4 also a broken access control - unauthenticated visitors could list a form\'s submissions (CVE-2026-77026). Update to Convert Forms 5.2.5.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-77026\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-77026\"},{\"element\":\"com_jem\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JEM - Joomla Event Manager\",\"below\":\"5.0.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere L\\u00fccken bis 5.0.0: privilegierte Remote-Code-Ausf\\u00fchrung (CVE-2026-77991), anonymes \\u00dcberschreiben\\/Ver\\u00f6ffentlichen von Joomla-Artikeln (CVE-2026-77034), fremde Events\\/Venues \\u00fcbernehmbar (CVE-2026-77035), Teilnehmerlisten f\\u00fcr jeden Eingeloggten lesbar (CVE-2026-77990). Fix in JEM 5.0.1.\",\"note_en\":\"Multiple flaws up to 5.0.0: privileged remote code execution (CVE-2026-77991), anonymous overwrite\\/publish of Joomla articles (CVE-2026-77034), other users\' events\\/venues hijackable (CVE-2026-77035), attendee lists readable by any logged-in user (CVE-2026-77990). Fixed in JEM 5.0.1.\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/jem-joomla-event-manager-disclosure\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/jem-joomla-event-manager-disclosure\\/\"},{\"element\":\"com_joomgallery\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JoomGallery\",\"below\":\"4.4.0\",\"above\":\"4.0.0\",\"severity\":\"medium\",\"note\":\"Zwei L\\u00fccken bis 4.3.x: CVE-2026-66916 (CVSS 6.9, unauth.) - passwortgesch\\u00fctzte Kategorien lie\\u00dfen sich \\u00fcber die JSON-Ansicht am Passwort vorbei auslesen; CVE-2026-66917 - Bearbeiter konnten fremde Inhalte \\u00fcbernehmen und JavaScript einschleusen. Update auf JoomGallery 4.4.0.\",\"note_en\":\"Two flaws up to 4.3.x: CVE-2026-66916 (CVSS 6.9, unauth.) - password-protected categories readable via the JSON view, bypassing the password; CVE-2026-66917 - editors could take over others\' content and inject JavaScript. Update to JoomGallery 4.4.0.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-66916\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-66916\"},{\"element\":\"com_j2store\",\"type\":\"component\",\"folder\":\"\",\"name\":\"J2Store \\/ J2Commerce\",\"below\":\"4.1.7\",\"above\":\"4.1.0\",\"severity\":\"critical\",\"note\":\"Mehrere schwere L\\u00fccken bis einschlie\\u00dflich 4.1.6 - auch 4.1.6 selbst ist betroffen: Bestellungen lassen sich per gef\\u00e4lschtem PayPal-R\\u00fcckruf ohne Zahlung als bezahlt markieren (CVE-2026-77999), eine fehlende Rechtepr\\u00fcfung erlaubt das Lesen und Ausf\\u00fchren von Dateien auf dem Server (CVE-2026-78069, CVSS 9.5), Warenk\\u00f6rbe sind ohne Login manipulierbar (CVE-2026-78064), und Adressen aus dem Gast-C\",\"note_en\":\"Multiple severe flaws up to and including 4.1.6 - 4.1.6 itself is affected: orders can be marked paid without payment via a forged PayPal callback (CVE-2026-77999), a missing authorization check allows reading and executing files on the server (CVE-2026-78069, CVSS 9.5), carts can be tampered with without login (CVE-2026-78064), and guest checkout addresses are readable by any logged-in account (C\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-78069\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-78069\"},{\"element\":\"com_j2store\",\"type\":\"component\",\"folder\":\"\",\"name\":\"J2Store \\/ J2Commerce\",\"below\":\"4.0.22\",\"above\":\"4.0.0\",\"severity\":\"critical\",\"note\":\"Mehrere schwere L\\u00fccken bis einschlie\\u00dflich 4.0.21 - auch 4.0.21 selbst ist betroffen: Bestellungen lassen sich per gef\\u00e4lschtem PayPal-R\\u00fcckruf ohne Zahlung als bezahlt markieren (CVE-2026-77999), eine fehlende Rechtepr\\u00fcfung erlaubt das Lesen und Ausf\\u00fchren von Dateien auf dem Server (CVE-2026-78069, CVSS 9.5), Warenk\\u00f6rbe sind ohne Login manipulierbar (CVE-2026-78064), und Adressen aus dem Gast\",\"note_en\":\"Multiple severe flaws up to and including 4.0.21 - 4.0.21 itself is affected: orders can be marked paid without payment via a forged PayPal callback (CVE-2026-77999), a missing authorization check allows reading and executing files on the server (CVE-2026-78069, CVSS 9.5), carts can be tampered with without login (CVE-2026-78064), and guest checkout addresses are readable by any logged-in account \",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-78069\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-78069\"},{\"element\":\"com_j2store\",\"type\":\"component\",\"folder\":\"\",\"name\":\"J2Store \\/ J2Commerce\",\"below\":\"3.3.22\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere schwere L\\u00fccken bis einschlie\\u00dflich 3.3.21 (Joomla-3-Linie) - auch 3.3.21 selbst ist betroffen: Bestellungen lassen sich per gef\\u00e4lschtem PayPal-R\\u00fcckruf ohne Zahlung als bezahlt markieren (CVE-2026-77999), eine fehlende Rechtepr\\u00fcfung erlaubt das Lesen und Ausf\\u00fchren von Dateien auf dem Server (CVE-2026-78069, CVSS 9.5), Warenk\\u00f6rbe sind ohne Login manipulierbar (CVE-2026-78064), und Adre\",\"note_en\":\"Multiple severe flaws up to and including 3.3.21 (Joomla 3 line) - 3.3.21 itself is affected: orders can be marked paid without payment via a forged PayPal callback (CVE-2026-77999), a missing authorization check allows reading and executing files on the server (CVE-2026-78069, CVSS 9.5), carts can be tampered with without login (CVE-2026-78064), and guest checkout addresses are readable by any lo\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-78069\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-78069\"},{\"element\":\"miniorangeoauth\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"miniOrange OAuth Client\",\"below\":\"3.2.0\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-77995 (kritisch): Auth-Umgehung - gef\\u00e4lschte Cookies gen\\u00fcgten, um sich ohne Anmeldung als beliebiger Nutzer (auch Super-User) einzuloggen. Nur das Update hilft (Cookie-basiert, nicht per Firewall). Update auf miniOrange OAuth Client 3.2.0.\",\"note_en\":\"CVE-2026-77995 (critical): authentication bypass - forged cookies were enough to log in as any user (incl. Super User) without signing in. Only the update helps (cookie-based, no firewall rule). Update to miniOrange OAuth Client 3.2.0.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-77995\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-77995\"},{\"element\":\"com_miniorange_saml\",\"type\":\"component\",\"folder\":\"\",\"name\":\"miniOrange SAML SP (SSO\\/ADFS\\/Google)\",\"below\":\"11.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-77998 (kritisch, CVSS 10.0): Auth-Umgehung \\u00fcber SAMLResponse - lose Signaturpr\\u00fcfung akzeptierte ung\\u00fcltige Signaturen, Login als beliebiger Nutzer (auch Admin). Nur das Update hilft (keine Firewall). Update auf SAML SSO 11.0.2 (ADFS-\\/Google-Edition: 6.4).\",\"note_en\":\"CVE-2026-77998 (critical, CVSS 10.0): auth bypass via SAMLResponse - a loose signature check accepted invalid signatures, login as any user (incl. admin). Only the update helps (no firewall). Update to SAML SSO 11.0.2 (ADFS\\/Google edition: 6.4).\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-77998\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-77998\"},{\"element\":\"sourcerer\",\"type\":\"plugin\",\"folder\":\"editors-xtd\",\"name\":\"Sourcerer (Regular Labs)\",\"below\":\"16.0.0\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-74253 (CVSS 10.0): unauthentifizierte Remote Code Execution - reflektierter oder unbest\\u00e4tigter Sourcerer-Code (alle Versionen bis 15.0.0) wurde serverseitig ausgef\\u00fchrt. HTProtect blockt g\\u00e4ngige Angriffe per WAF; voller Schutz erst mit Update auf Sourcerer 16.0.0.\",\"note_en\":\"CVE-2026-74253 (CVSS 10.0): unauthenticated remote code execution - reflected or unverified Sourcerer code (all versions up to 15.0.0) was executed on the server. HTProtect blocks common attacks via the WAF; full protection only after updating to Sourcerer 16.0.0.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-74253\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-74253\"},{\"element\":\"com_zoo\",\"type\":\"component\",\"folder\":\"\",\"name\":\"ZOO (YOOtheme)\",\"below\":\"4.1.66\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Unauth. Datei-Upload (RCE), SQL-Injection und Stored XSS (CVE-2026-76612) - bis 4.1.65. HTProtect blockt hochgeladene ausf\\u00fchrbare Dateien (Web-Shells); voller Schutz mit Update auf ZOO 4.1.66.\",\"note_en\":\"Unauth. file upload (RCE), SQL injection and stored XSS (CVE-2026-76612) - up to 4.1.65. HTProtect blocks uploaded executable files (web shells); full protection with the update to ZOO 4.1.66.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-76612\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-76612\"},{\"element\":\"yootheme\",\"type\":\"template\",\"folder\":\"\",\"name\":\"YOOtheme Pro\",\"below\":\"5.0.42\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Vier L\\u00fccken bis einschlie\\u00dflich 5.0.41 - auch 5.0.41 selbst ist betroffen: Stored XSS \\u00fcber das Standort-Feld (CVE-2026-77996) und eine fehlende Rechtepr\\u00fcfung, mit der sich Angaben zu beliebigen Modulen auslesen lassen (CVE-2026-77997). Dazu bis 5.0.40 eine SQL-Injektion (CVE-2026-76613, CVSS 8.6) und unbefugtes Lesen von Dateien (CVE-2026-75115) - beide schon von einem einfachen Redakteur\\/Autor\",\"note_en\":\"Four flaws up to and including 5.0.41 - 5.0.41 itself is affected: stored XSS via the location field (CVE-2026-77996) and a missing authorization check exposing information about arbitrary modules (CVE-2026-77997). Plus, up to 5.0.40, a SQL injection (CVE-2026-76613, CVSS 8.6) and unauthorized file read (CVE-2026-75115) - both exploitable by any contributor-level user. All four require a logged-in\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-77996\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-77996\"},{\"element\":\"com_jbusinessdirectory\",\"type\":\"component\",\"folder\":\"\",\"name\":\"J-Business Directory (CMS Junkie)\",\"below\":\"6.2.3\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische unauth. L\\u00fccken bis 6.2.2: Arbitrary File Upload\\/L\\u00f6schung per Path-Traversal (CVE-2026-75949), Ownership-\\u00dcbernahme (75950), IDOR (75951) und fehlende CSRF-Token (75952). HTProtect blockt die Datei-L\\u00f6schung per WAF; voller Schutz erst mit Update auf J-Business Directory 6.2.3.\",\"note_en\":\"Multiple critical unauthenticated flaws up to 6.2.2: arbitrary file upload\\/deletion via path traversal (CVE-2026-75949), ownership takeover (75950), IDOR (75951) and missing CSRF tokens (75952). HTProtect blocks the file deletion via the WAF; full protection only after updating J-Business Directory to 6.2.3.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-75949\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-75949\"},{\"element\":\"com_easydiscuss\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EasyDiscuss (StackIdeas)\",\"below\":\"5.0.16\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-21625: ACL-Umgehung im JSON-Output (Zugriff auf gesch\\u00fctzte Forendaten). Auf EasyDiscuss 5.0.16 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21625: access-control bypass in the JSON output exposing protected forum data. Update to EasyDiscuss 5.0.16 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-21625\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-21625\"},{\"element\":\"com_komento\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Komento (StackIdeas)\",\"below\":\"4.0.8\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2025-54294: SQL-Injection, ausnutzbar durch unprivilegierte Nutzer. Auf Komento 4.0.8 oder neuer aktualisieren.\",\"note_en\":\"CVE-2025-54294: SQL injection exploitable by unprivileged users. Update to Komento 4.0.8 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-54294\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-54294\"},{\"element\":\"nrframework\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Novarain \\/ Tassos Framework\",\"below\":\"6.1.0\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-21627 und CVE-2026-48906: \\u00dcber das Tassos-Framework lie\\u00df sich ohne Anmeldung fremder Programmcode einbinden. Auf 6.1 oder neuer aktualisieren - dazu gen\\u00fcgt das Update eines beliebigen Tassos-Produkts auf der Website.\",\"note_en\":\"CVE-2026-21627 and CVE-2026-48906: the Tassos framework allowed foreign program code to be included without logging in. Update to 6.1 or newer - updating any Tassos product on the site is enough.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/joomla-tassos-framework-novarain-framework-sicherheitsluecke\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/joomla-tassos-framework-novarain-framework-sicherheitsluecke\"},{\"element\":\"astroid\",\"type\":\"library\",\"folder\":\"\",\"name\":\"Astroid Framework\",\"below\":\"3.3.11\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-21628: unauthentifizierter Datei-Upload via AJAX-Endpunkt (Dropper in \\/images\\/). Auf 3.3.13 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21628: unauthenticated file upload via AJAX endpoint (dropper in \\/images\\/). Update to 3.3.13 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/joomla-astroid-framework-sicherheitsluecke-vulnerability\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/joomla-astroid-framework-sicherheitsluecke-vulnerability\"},{\"element\":\"helix3\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Helix3 (JoomShaper)\",\"below\":\"3.1.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-49049: unauthentifizierter com_ajax-Handler (onAjaxHelix3) ohne Login-\\/Rechtepr\\u00fcfung - Angreifer k\\u00f6nnen beliebige Dateien schreiben\\/l\\u00f6schen und Template-Parameter \\u00e4ndern (betroffen bis einschlie\\u00dflich 3.1.1). Auf Helix3 3.1.2 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-49049: unauthenticated com_ajax handler (onAjaxHelix3) with no login or permission check - attackers can write\\/delete arbitrary files and change template parameters (affected up to and including 3.1.1). Update to Helix3 3.1.2 or newer.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-49049\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-49049\"},{\"element\":\"shaper_helix3\",\"type\":\"template\",\"folder\":\"\",\"name\":\"Helix3 Template (shaper_helix3)\",\"below\":\"3.1.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-49049: das Helix3-Template ist \\u00fcber den unauthentifizierten com_ajax-Handler angreifbar - beliebige Dateien schreiben\\/l\\u00f6schen, Template-Parameter \\u00e4ndern (betroffen bis einschlie\\u00dflich 3.1.1). Das Template getrennt vom Plugin auf 3.1.2 aktualisieren.\",\"note_en\":\"CVE-2026-49049: the Helix3 template is reachable through the unauthenticated com_ajax handler - write\\/delete arbitrary files, change template parameters (affected up to and including 3.1.1). Update the template (separately from the plugin) to 3.1.2.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-49049\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-49049\"},{\"element\":\"helixultimate\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Helix Ultimate (JoomShaper)\",\"below\":\"2.2.10\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Kritische unauth. L\\u00fccken bis 2.2.9: com_ajax-Dispatcher ohne Rechtepr\\u00fcfung (Stored XSS, Datei-L\\u00f6schung; Fix 2.2.7) plus 12 weitere Fixes in 2.2.10 (Live-Preview-Bypass via ?helixMode=edit, Media-Upload, Mega-Men\\u00fc-XSS, Titel-Escaping). HTProtect blockt Kern-Angriffe per WAF. Joomla 4\\/5\\/6: auf 2.2.10 aktualisieren; Joomla 3 (Support eingestellt): JoomShapers J3-Security-Patch einspielen.\",\"note_en\":\"Critical unauth flaws up to 2.2.9: com_ajax dispatcher without permission checks (stored XSS, file deletion; fixed 2.2.7) plus 12 more fixes in 2.2.10 (Live Preview bypass via ?helixMode=edit, media upload, Mega Menu XSS, title escaping). HTProtect blocks core attacks via the WAF. Joomla 4\\/5\\/6: update to 2.2.10; Joomla 3 (support ended): install JoomShaper\'s J3 security patch.\",\"advisory\":\"https:\\/\\/htprotect.org\\/helix-ultimate\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/helix-ultimate\"},{\"element\":\"shaper_helixultimate\",\"type\":\"template\",\"folder\":\"\",\"name\":\"Helix Ultimate Template (shaper_helixultimate)\",\"below\":\"2.2.10\",\"above\":\"2.2.7\",\"severity\":\"critical\",\"note\":\"Das Helix-Ultimate-TEMPLATE (getrennt vom Plugin; aktualisiert sich nicht \\u00fcber den Joomla-Updater) ist von 2.2.7 bis 2.2.9 verwundbar: Media-Upload-Bypass, Path-Traversal, Broken Access Control und Stored XSS. Das Template separat auf 2.2.10 aktualisieren.\",\"note_en\":\"The Helix Ultimate TEMPLATE (separate from the plugin; does not update via the Joomla updater) is vulnerable from 2.2.7 to 2.2.9: media upload bypass, path traversal, broken access control and stored XSS. Update the template separately to 2.2.10.\",\"advisory\":\"https:\\/\\/htprotect.org\\/helix-ultimate\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/helix-ultimate\"},{\"element\":\"com_baforms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Balbooa Forms\",\"below\":\"2.4.3.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische unauth. RCE-L\\u00fccken bis 2.4.3.1 (eval-Injection CVE-2026-67364, Signatur-Feld CVE-2026-65880, Datei-Upload). HTProtect blockt Web-Shell-Uploads und die eval-\\/Signatur-RCE per WAF; voller Schutz erst mit Update auf Balbooa Forms 2.4.3.2 oder neuer.\",\"note_en\":\"Multiple critical unauthenticated RCE flaws up to 2.4.3.1 (eval injection CVE-2026-67364, signature field CVE-2026-65880, file upload). HTProtect blocks web-shell uploads and the eval\\/signature RCE via the WAF; full protection only after updating Balbooa Forms to 2.4.3.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-67364\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-67364\"},{\"element\":\"com_jce\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JCE Editor\",\"below\":\"2.9.99.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-48907: unauthentifizierter Webshell-Upload (profiles.import + plugin.rpc). Dringend auf JCE 2.9.99.6 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48907: unauthenticated webshell upload (profiles.import + plugin.rpc). Urgently update to JCE 2.9.99.6 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/jce-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/jce-sicherheitsluecke-joomla\"},{\"element\":\"com_rsfiles\",\"type\":\"component\",\"folder\":\"\",\"name\":\"RSFiles!\",\"below\":\"1.17.12\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Aktiver unauth. Datei-Upload -> RCE bis 1.17.11: anonymer Upload ohne Login-\\/Endungspr\\u00fcfung, .php ausf\\u00fchrbar. HTProtects Gast-Upload-Schutz blockt den Upload bereits. Auf RSFiles 1.17.12 aktualisieren.\",\"note_en\":\"Active unauthenticated file upload -> RCE up to 1.17.11: anonymous upload with no login\\/extension check, .php executable. The HTProtect guest-upload filter already blocks the upload. Update to RSFiles 1.17.12.\",\"advisory\":\"https:\\/\\/www.rsjoomla.com\\/blog\\/view\\/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html\",\"advisory_en\":\"https:\\/\\/www.rsjoomla.com\\/blog\\/view\\/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html\"},{\"element\":\"com_edocman\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EDocman\",\"below\":\"3.9\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Unauthentifizierte SQL-Injection bis 3.8: ein anonymer Besucher schleust \\u00fcber einen Filter-Parameter im Frontend SQL ein und liest die Datenbank aus (bis hin zu Zugangsdaten). Auf EDocman 3.9.0 aktualisieren.\",\"note_en\":\"Unauthenticated SQL injection up to 3.8: an anonymous visitor injects SQL via a front-end filter parameter and can read the database (up to credentials). Update to EDocman 3.9.0.\",\"advisory\":\"https:\\/\\/joomdonation.com\\/forum\\/edocman\\/82813-edocman-3-9-0-security-release---important-update-recommended.html\",\"advisory_en\":\"https:\\/\\/joomdonation.com\\/forum\\/edocman\\/82813-edocman-3-9-0-security-release---important-update-recommended.html\"},{\"element\":\"com_foranalytics\",\"type\":\"component\",\"folder\":\"\",\"name\":\"4Analytics\",\"below\":\"5.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-57833 und CVE-2026-58077: zwei unauthentifizierte, kritische Sicherheitsl\\u00fccken (ohne Login angreifbar) in allen Versionen vor 5.0.2. Dringend auf 4Analytics 5.0.2 aktualisieren.\",\"note_en\":\"CVE-2026-57833 and CVE-2026-58077: two unauthenticated, critical security flaws (exploitable without login) in all versions before 5.0.2. Update to 4Analytics 5.0.2 urgently.\",\"advisory\":\"https:\\/\\/weeblr.com\\/blog\\/critical-vulnerabilities-2026-07-15\",\"advisory_en\":\"https:\\/\\/weeblr.com\\/blog\\/critical-vulnerabilities-2026-07-15\"},{\"element\":\"com_quix\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Quix\",\"below\":\"6.2.1\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Unauthentifizierte SQL-Injection (CVSS 8.7, alle Versionen vor 6.2.1): ein anonymer Besucher kann die gesamte Datenbank auslesen. HTProtects Mini-WAF blockt den Angriff bereits. Auf Quix 6.2.1 aktualisieren.\",\"note_en\":\"Unauthenticated SQL injection (CVSS 8.7, all versions below 6.2.1): an anonymous visitor can read the entire database. HTProtect\'s mini-WAF already blocks the attack. Update to Quix 6.2.1.\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/quix-sql-injection-disclosure\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/quix-sql-injection-disclosure\\/\"},{\"element\":\"com_joomcck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JoomCCK\",\"below\":\"6.4.1\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"CVE-2026-49048: unauthentifizierte SQL-Injection \\u00fcber die Tag-Funktion - ein anonymer Besucher kann die Datenbank auslesen und ver\\u00e4ndern. HTProtects Mini-WAF blockt bereits. Auf JoomCCK 6.4.1 aktualisieren.\",\"note_en\":\"CVE-2026-49048: unauthenticated SQL injection via the tag function - an anonymous visitor can read and modify the database. HTProtect\'s mini-WAF already blocks it. Update to JoomCCK 6.4.1.\",\"advisory\":\"https:\\/\\/github.com\\/JoomCoder-com\\/JoomCCK\\/releases#release-6.4.1\",\"advisory_en\":\"https:\\/\\/github.com\\/JoomCoder-com\\/JoomCCK\\/releases#release-6.4.1\"},{\"element\":\"com_chronoforms8\",\"type\":\"component\",\"folder\":\"\",\"name\":\"ChronoForms\",\"below\":\"8.0.53\",\"above\":\"8.0.0\",\"severity\":\"high\",\"note\":\"CVE-2026-58148 (CVSS 8.7): unauthentifizierte gespeicherte XSS - anonym eingeschleustes JavaScript wird sp\\u00e4ter im Backend ausgef\\u00fchrt und kann die Admin-Sitzung \\u00fcbernehmen. Auf ChronoForms 8.0.53 aktualisieren.\",\"note_en\":\"CVE-2026-58148 (CVSS 8.7): unauthenticated stored XSS - JavaScript injected anonymously runs later in the backend and can take over the admin session. Update to ChronoForms 8.0.53.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-58148\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-58148\"},{\"element\":\"com_jdownloads\",\"type\":\"component\",\"folder\":\"\",\"name\":\"jDownloads\",\"below\":\"4.1.6\",\"above\":\"4.1.0\",\"severity\":\"high\",\"note\":\"Unauthentifizierter Datei-Upload (Versionen 4.1.0-4.1.5): anonym sind beliebige Dateien hochladbar, teils bis zur Codeausf\\u00fchrung. HTProtect blockt den Zugriff bereits (403). Auf jDownloads 4.1.6 aktualisieren.\",\"note_en\":\"Unauthenticated file upload (versions 4.1.0-4.1.5): anonymous visitors can upload arbitrary files, up to code execution on some servers. HTProtect already blocks direct access (403). Update to jDownloads 4.1.6.\",\"advisory\":\"https:\\/\\/www.jdownloads.com\\/index.php\\/news\\/jdownloads-4-1-6-secure-update-released.html\",\"advisory_en\":\"https:\\/\\/www.jdownloads.com\\/index.php\\/news\\/jdownloads-4-1-6-secure-update-released.html\"},{\"element\":\"com_dpcalendar\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DPCalendar\",\"below\":\"10.12.1\",\"above\":\"9.0.0\",\"severity\":\"high\",\"note\":\"DPCalendar (Joomla 4.4-6, vor 10.12.1): Ein angemeldeter Redakteur konnte \\u00fcber den Titel eines Veranstaltungsorts Schadcode einschleusen, der anschlie\\u00dfend bei jedem Besucher der Kartenansicht und im Termine-Modul ausgef\\u00fchrt wurde (CVE-2026-78071). Dazu kommen eine SQL-Injection \\u00fcber den Autor-Filter, die ein Besucher ohne Konto ausl\\u00f6sen konnte (HTProtect blockt sie bereits per Firewall), und \",\"note_en\":\"DPCalendar (Joomla 4.4-6, below 10.12.1): a logged-in editor could inject malicious code through a location title, which then ran for every visitor of the map view and the upcoming-events module (CVE-2026-78071). On top of that, an SQL injection via the author filter that a visitor without an account could trigger (HTProtect already blocks it via the firewall), and another one via saved articles. \",\"advisory\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/claude-security-audit-results\",\"advisory_en\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/claude-security-audit-results\"},{\"element\":\"com_dpcalendar\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DPCalendar\",\"below\":\"8.19.6\",\"above\":\"7.0.0\",\"severity\":\"high\",\"note\":\"DPCalendar f\\u00fcr Joomla 3 (7.0.0-8.19.5): Ein angemeldeter Redakteur konnte \\u00fcber den Titel eines Veranstaltungsorts Schadcode einschleusen, der anschlie\\u00dfend bei jedem Besucher der Kartenansicht und im Termine-Modul ausgef\\u00fchrt wurde (CVE-2026-78071). Dazu eine SQL-Injection \\u00fcber den Autor-Filter, die ein Besucher ohne Konto ausl\\u00f6sen konnte (HTProtect blockt sie bereits per Firewall). Wichtig: V\",\"note_en\":\"DPCalendar for Joomla 3 (7.0.0-8.19.5): a logged-in editor could inject malicious code through a location title, which then ran for every visitor of the map view and the upcoming-events module (CVE-2026-78071). On top of that, an SQL injection via the author filter that a visitor without an account could trigger (HTProtect already blocks it via the firewall). Important: version 8.19.5 was initiall\",\"advisory\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/claude-security-audit-results\",\"advisory_en\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/claude-security-audit-results\"},{\"element\":\"com_phocadownload\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Download\",\"below\":\"6.1.5\",\"above\":\"6.0.0\",\"severity\":\"high\",\"note\":\"Authentifizierter Datei-Upload -> RCE (6.0-6.1.2; HTProtects PHP-Schild verhindert die Ausf\\u00fchrung) sowie Reflected XSS \\u00fcber den Such-Parameter (bis 6.1.4). Auf Phoca Download 6.1.5 oder neuer aktualisieren.\",\"note_en\":\"Authenticated file upload -> RCE (6.0-6.1.2; HTProtect\'s PHP shield prevents execution) plus reflected XSS via the search parameter (up to 6.1.4). Update to Phoca Download 6.1.5 or newer.\",\"advisory\":\"https:\\/\\/www.phoca.cz\\/news\\/1508-phoca-download-version-6-1-5-released-security-release\",\"advisory_en\":\"https:\\/\\/www.phoca.cz\\/news\\/1508-phoca-download-version-6-1-5-released-security-release\"},{\"element\":\"com_phocamaps\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Maps\",\"below\":\"6.1.0\",\"above\":\"5.0.0\",\"severity\":\"medium\",\"note\":\"CVE-2026-65763: reflektiertes XSS (5.0.0-6.0.4) durch unzureichende Eingabepr\\u00fcfung - ein pr\\u00e4parierter Link f\\u00fchrt beim Besucher eingeschleustes JavaScript aus. Auf Phoca Maps 6.1.0 aktualisieren.\",\"note_en\":\"CVE-2026-65763: reflected XSS (5.0.0-6.0.4) via improper input validation - a crafted link runs injected JavaScript in a visitor\'s browser. Update to Phoca Maps 6.1.0.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65763\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65763\"},{\"element\":\"com_phocaguestbook\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Guestbook\",\"below\":\"6.1.1\",\"above\":\"5.0.0\",\"severity\":\"medium\",\"note\":\"CVE-2026-65762: reflektiertes XSS (5.0.0-6.1.0) durch unzureichende Eingabepr\\u00fcfung - ein pr\\u00e4parierter Link f\\u00fchrt beim Besucher eingeschleustes JavaScript aus. Auf Phoca Guestbook 6.1.1 (Security-Release) oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-65762: reflected XSS (5.0.0-6.1.0) via improper input validation - a crafted link runs injected JavaScript in the visitor\'s browser. Update to Phoca Guestbook 6.1.1 (security release) or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65762\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65762\"},{\"element\":\"com_acym\",\"type\":\"component\",\"folder\":\"\",\"name\":\"AcyMailing 6+\",\"below\":\"10.11.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-56292: unauthentifizierte SQL-Injection in AcyMailing 6+ (6.0.0-10.11.0), anonym die Datenbank inkl. Passwort-Hashes auslesbar. Weitere: CVE-2023-28731 (Upload\\/RCE), CVE-2026-3614 (Rechteausweitung). Auf AcyMailing 10.11.1 aktualisieren.\",\"note_en\":\"CVE-2026-56292: unauthenticated SQL injection in AcyMailing 6+ (6.0.0-10.11.0), anonymous read of the database incl. password hashes. Also: CVE-2023-28731 (upload\\/RCE), CVE-2026-3614 (privilege escalation). Update to AcyMailing 10.11.1.\",\"advisory\":\"https:\\/\\/htprotect.org\\/acymailing\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/acymailing\"},{\"element\":\"com_acymailing\",\"type\":\"component\",\"folder\":\"\",\"name\":\"AcyMailing Classic\",\"below\":\"4.9.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"AcyMailing Classic (End-of-Life): anonymer Datei-Upload\\/RCE der 3.x-\\u00c4ra und Backend-SQL-Injection CVE-2015-7338 (in 4.9.5 behoben); CVE-2018-9107 (CSV-Injection) ist niedrig. Auf eine unterst\\u00fctzte AcyMailing-Version migrieren.\",\"note_en\":\"AcyMailing Classic (end-of-life): anonymous file upload\\/RCE of the 3.x era and backend SQL injection CVE-2015-7338 (fixed in 4.9.5); CVE-2018-9107 (CSV injection) is low. Migrate to a supported AcyMailing version.\",\"advisory\":\"https:\\/\\/htprotect.org\\/acymailing\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/acymailing\"},{\"element\":\"com_igallery\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Ignite Gallery\",\"below\":\"5.4.1\",\"above\":\"5.0.0\",\"severity\":\"high\",\"note\":\"Ignite Gallery 5.0.0-5.4.0: Stored XSS (hoch) durch fehlendes Escaping bei Bild-Uploads, dazu SSRF und Rechteausweitung. Nur ausnutzbar mit Upload-\\/Bearbeitungsrecht. Auf Ignite Gallery 5.4.1 aktualisieren.\",\"note_en\":\"Ignite Gallery 5.0.0-5.4.0: stored XSS (high) via missing output escaping on image uploads, plus SSRF and privilege escalation. Only exploitable with upload\\/edit permission. Update to Ignite Gallery 5.4.1.\",\"advisory\":\"https:\\/\\/www.ignitegallery.com\\/documentation\\/changelog\",\"advisory_en\":\"https:\\/\\/www.ignitegallery.com\\/documentation\\/changelog\"},{\"element\":\"com_icagenda\",\"type\":\"component\",\"folder\":\"\",\"name\":\"iCagenda\",\"below\":\"4.0.12\",\"above\":\"4.0.0\",\"severity\":\"critical\",\"note\":\"CVE-2026-67365 (CVSS 9.2): unauthentifizierte SQL-Injection im Kalender-Modul, Datenbank ohne Login auslesbar. 4.0.12 behebt zudem CVE-2026-67366 und CVE-2026-48939. HTProtect blockt g\\u00e4ngige SQLi per WAF; voller Schutz mit Update auf iCagenda 4.0.12.\",\"note_en\":\"CVE-2026-67365 (CVSS 9.2): unauthenticated SQL injection in the calendar module, database readable without login. 4.0.12 also fixes CVE-2026-67366 and CVE-2026-48939. HTProtect blocks common SQLi via the WAF; full protection with the update to iCagenda 4.0.12.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-67365\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-67365\"},{\"element\":\"com_icagenda\",\"type\":\"component\",\"folder\":\"\",\"name\":\"iCagenda\",\"below\":\"3.9.15\",\"above\":\"3.2.1\",\"severity\":\"critical\",\"note\":\"CVE-2026-48939 (3.x-Linie f\\u00fcr Joomla 3): anonymer Datei-Upload im Event-Formular ohne Rechtepr\\u00fcfung. HTProtects Dateischild verhindert die Ausf\\u00fchrung bereits; voller Schutz erst mit Update auf iCagenda 3.9.15.\",\"note_en\":\"CVE-2026-48939 (3.x line for Joomla 3): anonymous file upload in the event form without a permission check. The HTProtect file shield already prevents execution; full protection only after updating iCagenda to 3.9.15.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/icagenda-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/icagenda-sicherheitsluecke-joomla\"},{\"element\":\"com_sppagebuilder\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP Page Builder\",\"below\":\"6.9.1\",\"above\":\"4.0.0\",\"severity\":\"critical\",\"note\":\"Sieben L\\u00fccken bis einschlie\\u00dflich 6.9.0: Ein Besucher OHNE Konto konnte \\u00fcber den \\u201eMehr laden\\\"-Endpunkt die Datenbank auslesen (CVE-2026-65876, CVSS 9.2). Dazu eine SQL-Injection \\u00fcber das Inhalts-Plugin (CVE-2026-78375, CVSS 8.6), eine Medienverwaltung, \\u00fcber die sich Dateien au\\u00dferhalb des vorgesehenen Ordners umbenennen und hochladen lie\\u00dfen (CVE-2026-81564, CVE-2026-81565), das Anlegen von \",\"note_en\":\"Seven flaws up to and including 6.9.0: a visitor with NO account could read the database via the load-more endpoint (CVE-2026-65876, CVSS 9.2). Plus an SQL injection via the content plugin (CVE-2026-78375, CVSS 8.6), a media manager that allowed files to be renamed and uploaded outside the intended folder (CVE-2026-81564, CVE-2026-81565), menu item creation without a permission check (CVE-2026-815\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/sp-page-builder-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/sp-page-builder-sicherheitsluecke-joomla\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.6.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische L\\u00fccken bis 3.6.4: anonymer Datei-Upload mit Codeausf\\u00fchrung (CVE-2026-56290\\/63048, die Fixes bis 3.6.2 waren unvollst\\u00e4ndig) und SQL-Injection (CVE-2026-74254). HTProtect blockt Upload und Ausf\\u00fchrung bereits; voller Schutz erst mit Update auf PageBuilder CK 3.6.5.\",\"note_en\":\"Several critical flaws up to 3.6.4: anonymous file upload with code execution (CVE-2026-56290\\/63048, fixes up to 3.6.2 were incomplete) and SQL injection (CVE-2026-74254). HTProtect already blocks the upload and execution; full protection only after updating PageBuilder CK to 3.6.5.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-63048\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-63048\"},{\"element\":\"com_eventbooking\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Events Booking\",\"below\":\"5.8.2\",\"above\":\"5.0\",\"severity\":\"high\",\"note\":\"Mehrere L\\u00fccken bis einschlie\\u00dflich 5.8.1 - auch 5.8.1 selbst ist betroffen: ohne jedes Konto lassen sich fremde Rechnungen zu Anmeldungen herunterladen, mit Namen, Anschriften und Betr\\u00e4gen (CVE-2026-63047). Vor 5.8.0 zus\\u00e4tzlich: anonymer Datei-Upload durch eine unsichere Voreinstellung (CVE-2026-60024, CVSS 9.8) sowie eine Schnittstelle, die zu jeder Benutzernummer Name und E-Mail preisgibt (ga\",\"note_en\":\"Multiple flaws up to and including 5.8.1 - 5.8.1 itself is affected: with no account at all, anyone can download other people\'s registration invoices including names, addresses and amounts (CVE-2026-63047). Before 5.8.0 additionally: anonymous file upload through an insecure default (CVE-2026-60024, CVSS 9.8) and an interface that returns the name and e-mail for any user number (entire user list r\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-63047\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-63047\"},{\"element\":\"com_djclassifieds\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DJ-Classifieds\",\"below\":\"3.11.2\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Aktiv ausgenutzte L\\u00fccke bis 3.11.1: anonymer Upload von Anzeigenbildern ohne Login und ohne Pr\\u00fcfung - ein Angreifer legt eine Schaddatei ab und \\u00fcbernimmt die Seite. Auf DJ-Classifieds 3.11.2 aktualisieren.\",\"note_en\":\"Actively exploited flaw up to 3.11.1: anonymous upload of ad images with no login and no checks - an attacker plants a malicious file and takes over the site. Update to DJ-Classifieds 3.11.2.\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/dj-classifieds-unauthenticated-file-upload\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/dj-classifieds-unauthenticated-file-upload\\/\"},{\"element\":\"com_gridbox\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Gridbox\",\"below\":\"2.20.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-61425 und weitere kritische L\\u00fccken bis 2.20.1: unbefugter Datei-Zugriff, Ordner-L\\u00f6schung, SQL-Injektionen und umgehbare Rechtepr\\u00fcfung. 2.20.1 reicht nicht - auf Balbooa Gridbox 2.20.2 aktualisieren.\",\"note_en\":\"CVE-2026-61425 and further critical flaws up to 2.20.1: unauthorized file access, folder deletion, SQL injections and authorization bypasses. 2.20.1 is not enough - update to Balbooa Gridbox 2.20.2.\",\"advisory\":\"https:\\/\\/www.balbooa.com\\/blog\\/gridbox\\/gridbox-2-20-2-security-release\",\"advisory_en\":\"https:\\/\\/www.balbooa.com\\/blog\\/gridbox\\/gridbox-2-20-2-security-release\"},{\"element\":\"com_joodb\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JooDatabase (JooDB)\",\"below\":\"5.1.0\",\"above\":\"4.0\",\"severity\":\"critical\",\"note\":\"CVE-2026-78080 (CVSS 9.3, JooDatabase Lite vor 5.1): Auf der oeffentlichen Katalog-Seite fliesst die Auswahl-Kennung (cid) ungeprueft in die Datenbank-Abfrage. Ein Besucher OHNE Konto kann damit fremde Daten aus der Datenbank auslesen - auch Zugangsdaten anderer Nutzer. Auf JooDatabase 5.1 aktualisieren. Bis dahin faengt die HTProtect-Firewall den Angriffsweg ab.\",\"note_en\":\"CVE-2026-78080 (CVSS 9.3, JooDatabase Lite before 5.1): on the public catalog page the selection identifier (cid) flows unchecked into the database query. A visitor with NO account can read arbitrary data from the database - including other users\' credentials. Update to JooDatabase 5.1. Until then the HTProtect firewall blocks the attack path.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-78080\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-78080\"},{\"element\":\"com_spproperty\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP Property (JoomShaper)\",\"below\":\"4.1.4\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Sechs L\\u00fccken bis einschlie\\u00dflich 4.1.3: Die \\u00f6ffentliche Immobiliensuche reicht Eingaben ungepr\\u00fcft in die Datenbank-Abfrage - ein Besucher OHNE Konto kann damit die Datenbank auslesen (CVE-2026-78082, CVSS 9.3). Dazu eingeschleuster Schadcode, der auch im Verwaltungsbereich angezeigt wird (CVE-2026-78302), fehlende Formular-Schutztoken bei Besichtigungsanfragen und Makler-Kontakt (CVE-2026-78083\",\"note_en\":\"Six flaws up to and including 4.1.3: the public property search passes input unchecked into the database query - a visitor with NO account can read the database (CVE-2026-78082, CVSS 9.3). Plus injected code that is also rendered in the administration area (CVE-2026-78302), missing form protection tokens on viewing requests and agent contact (CVE-2026-78083), a gallery manager without permission c\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-78082\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-78082\"},{\"element\":\"pkg_jmedia\",\"type\":\"package\",\"folder\":\"\",\"name\":\"JMedia (ThemeXpert)\",\"below\":\"1.6.0\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Zwei schwere L\\u00fccken bis einschlie\\u00dflich 1.5.4 (CVSS 9.4): Ein Besucher OHNE Konto konnte Dateien auf die Website hochladen, ohne dass der Dateityp gepr\\u00fcft wurde - damit l\\u00e4sst sich Schadcode einschleusen. Ebenso lie\\u00dfen sich fremde Dateien lesen, l\\u00f6schen und verschieben (CVE-2026-60034, CVE-2026-60032). Auf JMedia 1.6.0 oder neuer aktualisieren.\",\"note_en\":\"Two severe flaws up to and including 1.5.4 (CVSS 9.4): a visitor with NO account could upload files to the site without any file-type check - allowing malicious code to be planted. Files could likewise be read, deleted and moved (CVE-2026-60034, CVE-2026-60032). Update to JMedia 1.6.0 or newer.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-60034\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-60034\"},{\"element\":\"com_phocacommander\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Commander\",\"below\":\"6.1.4\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Mehrere L\\u00fccken bis einschlie\\u00dflich 6.1.3: \\u00dcber den eingebauten Dateimanager lie\\u00dfen sich Dateien au\\u00dferhalb des vorgesehenen Ordners lesen, hochladen, kopieren, verschieben und l\\u00f6schen (CVE-2026-66491, CVE-2026-66492, CVE-2026-66493). Angemeldete Benutzer konnten zudem eigenen Programmcode ausf\\u00fchren lassen (CVE-2025-54473, CVSS 9.2). Auf Phoca Commander 6.1.4 aktualisieren. Wichtig: Die \\u00e4lter\",\"note_en\":\"Several flaws up to and including 6.1.3: the built-in file manager allowed files outside the intended folder to be read, uploaded, copied, moved and deleted (CVE-2026-66491, CVE-2026-66492, CVE-2026-66493). Logged-in users could also have their own program code executed (CVE-2025-54473, CVSS 9.2). Update to Phoca Commander 6.1.4. Important: the older lines for Joomla 3, 4 and 5 receive no further \",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-66491\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-66491\"},{\"element\":\"pkg_csvi\",\"type\":\"package\",\"folder\":\"\",\"name\":\"RO CSVI\",\"below\":\"9.11.0\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Zwei L\\u00fccken bis einschlie\\u00dflich 9.10.x: Eine pr\\u00e4parierte Seite konnte angemeldete Redakteure unbemerkt Aktionen im Import-\\/Export-Werkzeug ausf\\u00fchren lassen (CVE-2026-65944, CVSS 8.8). Au\\u00dferdem konnte ein Besucher ohne Konto Verzeichnisse auf der Website anlegen (CVE-2026-65943). Auf RO CSVI 9.11.0 aktualisieren. Hinweis: Die \\u00e4lteren Reihen 7 und 8 werden nicht mehr gepflegt und erhalten diese\",\"note_en\":\"Two flaws up to and including 9.10.x: a prepared page could make logged-in editors perform actions in the import\\/export tool unnoticed (CVE-2026-65944, CVSS 8.8). A visitor without an account could also create directories on the site (CVE-2026-65943). Update to RO CSVI 9.11.0. Note: the older lines 7 and 8 are no longer maintained and do not receive this fix.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-65944\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-65944\"},{\"element\":\"acf\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Advanced Custom Fields (Tassos)\",\"below\":\"3.1.4\",\"above\":\"3.0.0\",\"severity\":\"high\",\"note\":\"CVE-2026-48906: \\u00dcber das mitgelieferte Tassos-Framework lie\\u00df sich ohne Anmeldung fremder Programmcode einbinden. Auf Advanced Custom Fields 3.1.4 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48906: the bundled Tassos framework allowed foreign program code to be included without logging in. Update Advanced Custom Fields to 3.1.4 or newer.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-48906\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-48906\"},{\"element\":\"acf\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Advanced Custom Fields (Tassos)\",\"below\":\"2.8.13\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-48906: \\u00dcber das mitgelieferte Tassos-Framework lie\\u00df sich ohne Anmeldung fremder Programmcode einbinden. F\\u00fcr Joomla 3 auf Advanced Custom Fields 2.8.13 aktualisieren.\",\"note_en\":\"CVE-2026-48906: the bundled Tassos framework allowed foreign program code to be included without logging in. On Joomla 3 update Advanced Custom Fields to 2.8.13.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-48906\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-48906\"},{\"element\":\"gsd\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Google Structured Data (Tassos)\",\"below\":\"6.2.0\",\"above\":\"6.0.0\",\"severity\":\"high\",\"note\":\"CVE-2026-48906: \\u00dcber das mitgelieferte Tassos-Framework lie\\u00df sich ohne Anmeldung fremder Programmcode einbinden. Auf Google Structured Data 6.2.0 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48906: the bundled Tassos framework allowed foreign program code to be included without logging in. Update Google Structured Data to 6.2.0 or newer.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-48906\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-48906\"},{\"element\":\"gsd\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Google Structured Data (Tassos)\",\"below\":\"5.6.12\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-48906: \\u00dcber das mitgelieferte Tassos-Framework lie\\u00df sich ohne Anmeldung fremder Programmcode einbinden. F\\u00fcr Joomla 3 auf Google Structured Data 5.6.12 aktualisieren.\",\"note_en\":\"CVE-2026-48906: the bundled Tassos framework allowed foreign program code to be included without logging in. On Joomla 3 update Google Structured Data to 5.6.12.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-48906\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-48906\"},{\"element\":\"com_smilepack\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Smile Pack (Tassos)\",\"below\":\"2.1.1\",\"above\":\"2.0.0\",\"severity\":\"high\",\"note\":\"CVE-2026-48906: \\u00dcber das mitgelieferte Tassos-Framework lie\\u00df sich ohne Anmeldung fremder Programmcode einbinden. Auf Smile Pack 2.1.1 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48906: the bundled Tassos framework allowed foreign program code to be included without logging in. Update Smile Pack to 2.1.1 or newer.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-48906\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-48906\"},{\"element\":\"com_smilepack\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Smile Pack (Tassos)\",\"below\":\"1.2.7\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-48906: \\u00dcber das mitgelieferte Tassos-Framework lie\\u00df sich ohne Anmeldung fremder Programmcode einbinden. F\\u00fcr Joomla 3 auf Smile Pack 1.2.7 aktualisieren.\",\"note_en\":\"CVE-2026-48906: the bundled Tassos framework allowed foreign program code to be included without logging in. On Joomla 3 update Smile Pack to 1.2.7.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-48906\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-48906\"},{\"element\":\"com_tassoscodesnippets\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Code Snippets (Tassos)\",\"below\":\"1.0.1\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-48906: \\u00dcber das mitgelieferte Tassos-Framework lie\\u00df sich ohne Anmeldung fremder Programmcode einbinden. Auf Code Snippets 1.0.1 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48906: the bundled Tassos framework allowed foreign program code to be included without logging in. Update Code Snippets to 1.0.1 or newer.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-48906\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-48906\"},{\"element\":\"com_cck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SEBLOD\",\"below\":\"3.30.0\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-66914: \\u00dcber die Download-Funktion lie\\u00dfen sich Dateien au\\u00dferhalb des vorgesehenen Ordners abrufen. F\\u00fcr Joomla 3 auf SEBLOD 3.30.0 aktualisieren.\",\"note_en\":\"CVE-2026-66914: the download function allowed files outside the intended folder to be fetched. On Joomla 3 update SEBLOD to 3.30.0.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-66914\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-66914\"},{\"element\":\"com_cck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SEBLOD\",\"below\":\"4.7.0\",\"above\":\"4.0.0\",\"severity\":\"high\",\"note\":\"CVE-2026-66914: \\u00dcber die Download-Funktion lie\\u00dfen sich Dateien au\\u00dferhalb des vorgesehenen Ordners abrufen. Auf SEBLOD 4.7.0 aktualisieren.\",\"note_en\":\"CVE-2026-66914: the download function allowed files outside the intended folder to be fetched. Update SEBLOD to 4.7.0.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-66914\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-66914\"},{\"element\":\"com_cck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SEBLOD\",\"below\":\"6.0.1\",\"above\":\"5.0.0\",\"severity\":\"high\",\"note\":\"CVE-2026-66914: \\u00dcber die Download-Funktion lie\\u00dfen sich Dateien au\\u00dferhalb des vorgesehenen Ordners abrufen. Auf SEBLOD 6.0.1 aktualisieren.\",\"note_en\":\"CVE-2026-66914: the download function allowed files outside the intended folder to be fetched. Update SEBLOD to 6.0.1.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-66914\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-66914\"},{\"element\":\"com_sexypolling\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Sexy Polling Reloaded\",\"below\":\"5.6.1\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-78072: Die \\u00f6ffentliche Umfrage-Funktion reichte Eingaben ungepr\\u00fcft in die Datenbank-Abfrage - ein Besucher ohne Konto konnte damit die Datenbank auslesen. Auf Sexy Polling 5.6.1 aktualisieren.\",\"note_en\":\"CVE-2026-78072: the public poll function passed input unchecked into the database query - a visitor without an account could read the database. Update Sexy Polling to 5.6.1.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-78072\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-78072\"}],\"php_min\":\"8.1\",\"fetched\":\"2026-09-18 13:40:48\",\"fetched_ts\":1790377596,\"etag\":\"\\\"6aad3e8f-1aa16\\\"\",\"modified\":\"Fri, 18 Sep 2026 13:37:19 GMT\",\"joomla_latest\":{\"3\":\"3.10.12\",\"4\":\"4.4.14\",\"5\":\"5.4.8\",\"6\":\"6.1.3\"},\"joomla_latest_ts\":1790369918,\"joomla_latest_try\":1790369918},\"htp_malware\":{\"schema\":1,\"version\":\"2026-09-10.25388e\",\"sigs\":[{\"id\":\"backdoor-prepend-sshkey\",\"all\":[\"auto_prepend_file\",\"authorized_keys\"]},{\"id\":\"cred-stealer-ctfaudit\",\"any\":[\"x-ctf-audit\",\"jlib_audit_gid\"]},{\"id\":\"upload-shell-form\",\"all\":[\"move_uploaded_file\",\"check directory permissions\"]},{\"id\":\"sppb-iconfont-shell\",\"any\":[\"sppbwhoami\"]},{\"id\":\"remote-eval-loader\",\"all\":[\"eval(\\\"?>\\\"\"],\"any\":[\"fetchcontentfromurl\",\"file_get_contents(\\\"http\",\"file_get_contents(\'http\"]},{\"id\":\"seo-doorway-slot\",\"any\":[\"slot gacor\",\"situs slot gacor\"]},{\"id\":\"filemanager-backdoor-data\",\"all\":[\"<?php exit;?>{\",\"\\\"groupinfo\\\"\",\"\\\"sizemax\\\"\"]},{\"id\":\"encrypted-eval-openssl\",\"all\":[\"openssl_raw_data\",\"aes-256-cbc\"],\"not\":[\"openssl_decrypt\",\"openssl_encrypt\"]},{\"id\":\"0xnix-split-encrypted\",\"all\":[\"0xnix encrypted code\"]},{\"id\":\"upload-shell-devco1\",\"all\":[\"move_uploaded_file\",\"devco1\"]},{\"id\":\"upload-shell-uname-form\",\"all\":[\"move_uploaded_file\",\"php_uname\",\"multipart\\/form-data\"]},{\"id\":\"hacktool-adminer\",\"all\":[\"adminer_errors\",\"idf_unescape\"]},{\"id\":\"webshell-range-obfuscator\",\"all\":[\"\\\"r\\\".\\\"a\\\".\\\"n\\\".\\\"g\\\".\\\"e\\\"\",\"eval\"]},{\"id\":\"webshell-md5quad-gate\",\"all\":[\"md5(md5(md5(md5(\",\"eval\"]},{\"id\":\"remote-loader-stream-include\",\"any\":[\"include stream_get_meta_data\",\"require stream_get_meta_data\",\"include(stream_get_meta_data\",\"require(stream_get_meta_data\"]},{\"id\":\"webshell-dual-uploader\",\"all\":[\"remote_url\",\"name=\\\"_upl\\\"\",\"name=\\\"_remote\\\"\"]},{\"id\":\"webshell-comment-obfuscator\",\"all\":[\"-*\\/\\/\\/\",\"\\\"~\\\"\"]},{\"id\":\"eval-openssl-shell\",\"label\":\"eval(openssl_decrypt) webshell\",\"all\":[\"eval(openssl_decrypt(\"]},{\"id\":\"dropper-drivergenius-c2\",\"label\":\"Remote-fetch dropper (drivergenius C2)\",\"all\":[\"drivergenius.it.com\"]},{\"id\":\"dropper-backdate-disguise\",\"label\":\"Remote-fetch dropper (mtime-forge + disguise)\",\"all\":[\"getreferencefiletime\",\"generatefilename\"]},{\"id\":\"js-inject-fake-cleaned\",\"label\":\"JS injection w\\/ fake \\\"cleaned\\/safe\\\" comment\",\"all\":[\"artifacts of previous malicious infection\",\"dangerous code has been removed\"]},{\"id\":\"linkforge-seo-injector\",\"label\":\"LinkForge SEO backlink injector\",\"all\":[\"linkforge.cc\"]},{\"id\":\"seo-doorway-cloak\",\"label\":\"SEO cloaking doorway (Thai gambling, fake sitemap)\",\"all\":[\"output_sitemap_page\",\"is_from_google\",\"send_404_and_exit\"]},{\"id\":\"helix-ultimate-xss\",\"label\":\"Helix Ultimate mega-menu XSS campaign\",\"any\":[\"xss.report\",\"_hu_inject\",\"_huinject\",\"sessionstorage._hxd\"]},{\"id\":\"gsocket-c2\",\"label\":\"gsocket reverse-shell C2 marker\",\"any\":[\"gs_args\"]},{\"id\":\"cloak-engine-thiscitze\",\"label\":\"thiscitze SEO cloaking engine\",\"all\":[\"thiscitze\"]},{\"id\":\"cloak-doorway-jsurl-jumpurl\",\"label\":\"Thai gambling SEO cloaking\\/doorway injector\",\"all\":[\"$js_url\",\"$jump_url\"]},{\"id\":\"cn-aes-loader\",\"label\":\"AES-decrypt + gzinflate eval loader\",\"all\":[\"openssl_decrypt\",\"gzinflate\",\"eval(\\\"?>\\\"\"]},{\"id\":\"cn-loader-tag\",\"label\":\"Chinese \'PHP code security loader\' tag\",\"all\":[\"php\\u4ee3\\u7801\\u5b89\\u5168\\u52a0\\u8f7d\\u5668\"]},{\"id\":\"menu-api-filemanager\",\"label\":\"MENU_API file-manager webshell\",\"all\":[\"menu_api_password\"]},{\"id\":\"remote-eval-curl\",\"label\":\"curl remote-fetch eval loader\",\"all\":[\"eval(\\\"?>\\\"\",\"curl_exec\"]},{\"id\":\"bujang-c2\",\"label\":\"Remote-fetch loader (bujang.online C2)\",\"all\":[\"bujang.online\"]},{\"id\":\"tinyfilemanager-tool\",\"label\":\"Tiny File Manager (webshell-capable file manager)\",\"all\":[\"tinyfilemanager\"]},{\"id\":\"webshell-split-strrev-system\",\"all\":[\"\\\"st\\\".\\\"rr\\\".\\\"ev\\\"\",\"\\\"s\\\".\\\"ys\\\".\\\"tem\\\"\"]},{\"id\":\"webshell-split-b64-fgc\",\"all\":[\"\\\"base6\\\".\\\"4_d\\\".\\\"ecode\\\"\",\"\\\"fil\\\".\\\"e_get_cont\\\".\\\"ents\\\"\"]},{\"id\":\"octal-superglobal\",\"label\":\"Superglobal aus Oktal-Zeichen zusammengebaut (Cookie-Dropper)\",\"all\":[\"${\",\"\\\\137\"],\"any\":[\"\\\\103\",\"\\\\107\\\\105\\\\124\",\"\\\\120\\\\117\\\\123\\\\124\",\"\\\\122\\\\105\\\\121\",\"\\\\123\\\\105\\\\122\",\"\\\\106\\\\111\\\\114\"]},{\"id\":\"hex-superglobal\",\"label\":\"Superglobal aus Hex-Zeichen zusammengebaut\",\"all\":[\"${\",\"\\\\x5f\"],\"any\":[\"\\\\x43\",\"\\\\x47\\\\x45\\\\x54\",\"\\\\x50\\\\x4f\\\\x53\\\\x54\",\"\\\\x52\\\\x45\\\\x51\",\"\\\\x53\\\\x45\\\\x52\",\"\\\\x46\\\\x49\\\\x4c\"]},{\"id\":\"upload-parent-dir\",\"label\":\"Upload-Hintertuer: Ablage in den uebergeordneten Ordner\",\"all\":[\"move_uploaded_file\"],\"any\":[\"\'..\\/\'.$_files\",\"\'..\\/\' .$_files\",\"\'..\\/\'. $_files\",\"\'..\\/\' . $_files\",\"\\\"..\\/\\\".$_files\",\"\\\"..\\/\\\" .$_files\",\"\\\"..\\/\\\". $_files\",\"\\\"..\\/\\\" . $_files\"]},{\"id\":\"mixed-escape-superglobal\",\"label\":\"Superglobal aus gemischten Hex- und Oktal-Zeichen\",\"all\":[\"${\",\"\\\\x52\\\\x45\\\\121\\\\125\\\\x45\\\\123\\\\x54\"]},{\"id\":\"hex-zip-wrapper\",\"label\":\"Archiv-Wrapper in Hex-Schreibweise versteckt\",\"all\":[\"\\\\x7a\\\\x69\\\\x70\\\\x3a\\\\x2f\\\\x2f\"],\"any\":[\"include\",\"require\",\"eval(\",\"assert(\"]},{\"id\":\"godzilla-webshell\",\"label\":\"Godzilla webshell (XOR\\/Base64 payload channel)\",\"all\":[\"getbasicsinfo\"],\"any\":[\"eval(\",\"assert(\",\"base64_decode\",\"$_session[\"]},{\"id\":\"godzilla-xor-keyrotate\",\"label\":\"Godzilla webshell XOR key rotation (16-byte)\",\"all\":[\"$i+1&15\"],\"any\":[\"eval(\",\"assert(\",\"base64_decode\",\"$_session[\",\"$_post[\",\"$_request[\"]},{\"id\":\"godzilla-inplace-xor-loop\",\"label\":\"In-place XOR decode loop feeding eval (Godzilla family)\",\"all\":[\"[$i]^$\"],\"any\":[\"eval(\",\"assert(\",\"base64_decode\"]}],\"names\":[{\"id\":\"probe-d1337\",\"m\":[\"_d1337_\"],\"label\":\"d1337 write-access probe \\/ dropper marker\"},{\"id\":\"probe-write-test\",\"m\":[\"_probe_\"],\"label\":\"generic write-access probe marker (_probe_)\"}],\"scan_ext\":[],\"ack\":[\"6608daed700e0afc330788b2a272ca8d\",\"67b5f9a00c7aabf34261c715aeeaadba\",\"9812b693256a0c306cc53368559c7a4b\",\"ec96a3bed6681af996fd37f0818cba6b\",\"abfe3b7513994ae6ac2f33129b5f6e7b\",\"fb2e76c5ebafc2b8ea82e0d35d45fa02\",\"2ec54ce00420cd41dfae5abedc9edcb7\",\"02c1a767857c55d31cae7277bc43bac2\",\"573a5e7374be2925911b552d485a28f3\",\"cdf24443c39d943f8750d4a4420e6581\",\"99af93b919c5b6bc14a82382c39010ec\",\"55e704bb88a8f9ab0d756976c527516b\",\"981b4f5e07bf9cd1249d60d659e4ef93\",\"87d978102ed075a8e58074a0d3595c30\",\"85648deb8324a11400ecaebcfd04ae16\",\"323707d28051b4cbf161420f5f1bb499\",\"19104a261abbdffe7cd1713949b286cf\",\"a72013015988ad7d978ce9841a9668dd\",\"a8af9b93d27c774601e1d8a902145bd7\",\"82c8de717e67a620ca503a1a01a7d909\",\"a8192a3cf6279862054cb3092dad82bf\",\"eae8beb708347cfe54bf87506b572f41\",\"5db6f4cdd20dfee86e05110a2276d748\",\"872e97edc1d4247d2ed86d35f468ff88\",\"da9c67c9b7be2d5a7eb9113d76119abc\",\"d0c5a881e845f93a72e1450259de0d33\",\"ea531694f501221b61a324d3754da603\",\"b8333a512d949684c91c9dd907f9cb0c\",\"2c57aea21d161fe5761ffab0abff8228\",\"93117860cd06939707a4ff1797bebb40\",\"7f58961ebcc0db81b16c2d16072fb084\",\"760423f79cedc17e78df95505e93f0c7\",\"d8b0c0f2faf44495f7954fe826720bad\",\"b9b6b8553113e745ebef3251b5d223b9\",\"3e5d03ecb5de8ab2ff1790d7b78bee24\",\"0cd3f898084fe66b062ab5162d2b370c\",\"deb26b6603b6edd8381f6c77fc53cace\",\"0855cf0d6a33b86a8506aeeb769e4343\",\"bcfa5def6057812cba39996c13c1feb3\",\"b719915e7d46c753fe4aeb7a6b8e7fea\",\"913459ac4f3b49356595a341f9b2ac03\",\"e902a6e687aa6cc1398cce5a55fb9905\",\"619cb219bc0492b46608717514204eeb\",\"3ac0ed83859d47acc729c20767afb925\"],\"community\":0,\"fp\":[{\"all\":[\"easycalccheckplus\"],\"only\":[\"rce\"],\"id\":\"ecc-plus-doc-rce\"},{\"all\":[\"phpoffice\\\\phpspreadsheet\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"phpspreadsheet-lib\"},{\"any\":[\"cp_errordocument\",\"status-reason\"],\"not\":[\"<!--#exec\",\"<?\"],\"only\":[\"shtml\"],\"id\":\"plesk-error-shtml\"},{\"all\":[\"gumlet\",\"data:\\/\\/application\\/octet-stream\"],\"only\":[\"wrapper\"],\"id\":\"gumlet-imageresize-datawrapper\"},{\"all\":[\"data:\\/\\/image\",\"exif_read_data\"],\"only\":[\"wrapper\"],\"id\":\"exif-data-wrapper\"},{\"all\":[\"phpoffice\\\\phpword\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"phpword-lib\"},{\"all\":[\"box\\\\spout\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"box-spout-lib\"},{\"all\":[\"sarciszewski\\\\phpfuture\"],\"only\":[\"wrapper\"],\"id\":\"php-future-lib\"},{\"all\":[\"baformsmodelform\"],\"only\":[\"feed:upload-shell-uname-form\"],\"id\":\"fp-baforms-model\"},{\"all\":[\"quixnxt\"],\"only\":[\"goto\"],\"id\":\"fp-quix-goto\"},{\"all\":[\"varexporter\"],\"only\":[\"goto\"],\"id\":\"fp-symfony-varexporter-goto\"},{\"all\":[\"valorapps.com\"],\"only\":[\"idxbuild\"],\"id\":\"fp-easyfolderlisting-changelog\"},{\"all\":[\"matomo.org\"],\"only\":[\"rce\"],\"id\":\"fp-matomo-rce\"},{\"all\":[\"namespace tracy\"],\"only\":[\"phtml\"],\"id\":\"fp-tracy-phtml\"},{\"all\":[\"guzzlehttp\",\"requestfsm\"],\"only\":[\"goto\"],\"id\":\"fp-guzzle-requestfsm\"},{\"all\":[\"siteguarding.com\",\"siteguarding_server_ip1\"],\"only\":[\"feed:upload-shell-uname-form\"],\"id\":\"fp-siteguarding-agent\"},{\"all\":[\"muruguard\"],\"only\":[\"feed:helix-ultimate-xss\"],\"id\":\"fp-muruguard-scanner\"},{\"all\":[\"<svg\"],\"not\":[\"<script\",\"<?php\",\"<?=\",\"onload=\",\"onerror=\",\"onmouseover=\",\"onclick=\",\"onfocus=\",\"javascript:\",\"<foreignobject\"],\"only\":[\"tmp_exec\"],\"id\":\"fp-benign-svg-tmp\"}],\"seo\":{\"weights\":[],\"keywords\":[],\"sigs\":[]},\"recall\":[],\"fetched\":\"2026-09-10 20:56:05\",\"fetched_ts\":1790373917,\"etag\":\"\\\"6aa2dc47-2ac4\\\"\",\"modified\":\"Thu, 10 Sep 2026 16:35:19 GMT\"},\"htp_incidents\":[]}'
WHERE `type` = 'component' AND `element` = 'com_htprotect'