Attackers Exploit 10-Rated Joomla Flaws in iCagenda, Balbooa Forms
Updated
Updated · The Register · Jul 20
Attackers Exploit 10-Rated Joomla Flaws in iCagenda, Balbooa Forms
2 articles · Updated · The Register · Jul 20
Summary
Critical bugs in Joomla’s iCagenda and Balbooa Forms extensions are being actively exploited, exposing sites running the add-ons on the open-source CMS.
CVSS 10 flaws in the two extensions give attackers a severe path into vulnerable websites, turning unpatched Joomla deployments into immediate targets.
Joomla powers about 1 million sites worldwide, widening the potential impact beyond a niche plugin issue to a broad slice of public-facing web infrastructure.