,

Vulnerability Watch No59

🗑️ Joomla Fabrik List Controller Allows Unauthorized Data Deletion
Fabrik administrators should patch urgently to prevent destructive actions. Unauthorized table truncation can cause significant data loss.
CVE-2026-76596 is a HIGH vulnerability with CVSS 8.7 affecting the Joomla Fabrik extension by fabrikar.com before version 4.7.2. The list.doempty endpoint lacks ACL protection, allowing a simple GET request to empty target list tables.
🔗 Read more 🔗
Source: NVD

🔎 Joomla Fabrik Reveals Database Structure to Unauthenticated Users
Joomla administrators should include this in their next urgent patch cycle. Database metadata exposure can help attackers prepare further attacks.
CVE-2026-76599 is a HIGH vulnerability with CVSS 8.7 affecting the Joomla Fabrik extension by fabrikar.com before version 4.7.2. The ajax_tables method can disclose arbitrary database tables and columns without authentication.
🔗 Read more 🔗
Source: NVD

📂 Joomla Fabrik Allows Unauthenticated Directory Listing
Fabrik users should patch promptly. Directory listings can reveal sensitive application structure and files.
CVE-2026-76598 is a HIGH vulnerability with CVSS 8.7 affecting the Joomla Fabrik extension by fabrikar.com before version 4.7.2. The onAjax_getFolders method allows arbitrary directory listings without authentication.
🔗 Read more 🔗
Source: NVD

📤 Joomla Fabrik Permits Unauthenticated File Uploads
Administrators should update Fabrik quickly. Even non-executable uploads can create security risks and support follow-on attacks.
CVE-2026-76597 is a HIGH vulnerability with CVSS 8.7 affecting the Joomla Fabrik extension by fabrikar.com before version 4.7.2. The list email plugin allows unauthenticated uploads of non-executable files to the web root.
🔗 Read more 🔗
Source: NVD

🚨 WordPress WS Form Plugin Exposes Critical PHP Object Injection Flaw
WordPress site owners using this plugin should update immediately. The risk depends on the presence of another plugin or theme with a POP chain, but the critical rating makes remediation a priority.
CVE-2026-4703 is a CRITICAL vulnerability with CVSS 9.8 affecting the WS Form LITE – Drag & Drop Contact Form Builder plugin for WordPress. Versions up to and including 1.10.80 are vulnerable to PHP Object Injection through deserialization of untrusted form submission meta values, potentially enabling file deletion, data access, or code execution if a POP chain exists.
🔗 Read more 🔗
Source: NVD

⚠️ Joomla Fabrik Extension Misses Access Controls in Comment Endpoint
Joomla administrators running Fabrik should patch as soon as possible. Missing access controls can expose administrative functions to unauthenticated attackers.
CVE-2026-77992 is a CRITICAL vulnerability with CVSS 9.5 affecting the Joomla Fabrik extension by fabrikar.com before version 4.7.2. The onUpdateComment endpoint failed to perform access checks, allowing unauthorized actions against affected installations.
🔗 Read more 🔗
Source: NVD

🔓 Joomla Fabrik Download Element Allows Unauthorized Access
Fabrik users should upgrade immediately. The maximum severity score indicates this issue should be treated as an urgent patching item.
CVE-2026-76607 is a CRITICAL vulnerability with CVSS 10 affecting the Joomla Fabrik extension by fabrikar.com before version 4.7.3. The download element has a missing ACL check that can allow unauthorized users to access protected functionality.
🔗 Read more 🔗
Source: NVD

📁 Joomla Fabrik Image Element Hit by Path Traversal Bug
Administrators should patch affected Fabrik installations immediately. Path traversal issues can expose sensitive server files if successfully exploited.
CVE-2026-76606 is a CRITICAL vulnerability with CVSS 10 affecting the Joomla Fabrik extension by fabrikar.com before version 4.7.3. The image element contains a path traversal flaw that may allow attackers to access unintended files.
🔗 Read more 🔗
Source: NVD

💥 Joomla Fabrik Image Element Enables Remote Code Execution
Fabrik administrators should prioritize this update immediately. Remote code execution flaws can lead to full site compromise.
CVE-2026-76605 is a CRITICAL vulnerability with CVSS 10 affecting the Joomla Fabrik extension by fabrikar.com before version 4.7.3. The image element contains a remote code execution issue that can allow attackers to run code on affected systems.
🔗 Read more 🔗
Source: NVD

🔥 Joomla Fabrik PHP Form Element Allows Unauthenticated Code Execution
Organizations using Fabrik should patch without delay. An unauthenticated RCE issue can put the entire Joomla site at immediate risk.
CVE-2026-76604 is a CRITICAL vulnerability with CVSS 10 affecting the Joomla Fabrik extension by fabrikar.com before version 4.7.3. The PHP form element executes user-provided code, allowing unauthenticated remote code execution.
🔗 Read more 🔗
Source: NVD

🛢️ Joomla Fabrik Lists Expose Critical SQL Injection Flaw
Fabrik deployments should be patched urgently. Unauthenticated SQL injection can expose sensitive database contents.
CVE-2026-76602 is a CRITICAL vulnerability with CVSS 9.3 affecting the Joomla Fabrik extension by fabrikar.com before version 4.7.3. The order parameter in list models is used in queries without validation, allowing unauthenticated SQL injection and database reads.
🔗 Read more 🔗
Source: NVD

💉 Joomla Fabrik Filter Parameter Exposes SQL Injection
Organizations running Fabrik should patch immediately. Unauthenticated SQL injection can provide attackers broad access to application data.
CVE-2026-76571 is a CRITICAL vulnerability with CVSS 9.3 affecting the Joomla Fabrik extension by fabrikar.com before version 4.7.3. The condition parameter is inserted into SQL WHERE clauses without validation, allowing unauthenticated SQL injection and full database reads.
🔗 Read more 🔗
Source: NVD