<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Joomla — PoC Archive</title><link>https://poc.intelseclab.com/tags/joomla/</link><description>Latest proof-of-concept entries.</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Mon, 27 Jul 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://poc.intelseclab.com/tags/joomla/index.xml" rel="self" type="application/rss+xml"/><item><title>Joomla Helix Ultimate Framework — Unauthenticated Arbitrary File Deletion (CVE-2026-57830)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-57830-joomla-helix-ultimate-file-deletion/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-57830-joomla-helix-ultimate-file-deletion/</guid><description>Critical severity (CVSS 9.1) — web · CVE-2026-57830. Status: Weaponized. Affects: Helix Ultimate Framework (plg_system_helixultimate), the JoomShaper Joomla template framework bundled with virtually every JoomShaper Joomla template. Tags: joomla, helix-ultimate, joomshaper, arbitrary-file-deletion, cwe-862, unauthenticated, csrf-token-only-check.</description><category>web</category><category>Critical</category><category>joomla</category><category>helix-ultimate</category><category>joomshaper</category><category>arbitrary-file-deletion</category><category>cwe-862</category><category>unauthenticated</category><category>csrf-token-only-check</category></item><item><title>Joomla Balbooa Forms Unauthenticated Arbitrary File Upload → RCE (CVE-2026-56291)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</link><pubDate>Mon, 27 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-27_cve-2026-56291-joomla-balbooa-forms-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56291. Status: Weaponized. Affects: Balbooa Forms (com_baforms) — third-party Joomla! extension by balbooa.com. Tags: joomla, balbooa-forms, file-upload, webshell, unauthenticated, rce, kev, actively-exploited, cwe-434.</description><category>web</category><category>Critical</category><category>joomla</category><category>balbooa-forms</category><category>file-upload</category><category>webshell</category><category>unauthenticated</category><category>rce</category><category>kev</category><category>actively-exploited</category><category>cwe-434</category></item><item><title>Unauthenticated Arbitrary File Upload RCE in iCagenda for Joomla (CVE-2026-48939)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-48939-icagenda-joomla-file-upload-rce/</link><pubDate>Sat, 11 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-11_cve-2026-48939-icagenda-joomla-file-upload-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-48939. Status: Weaponized (public PoC available, actively exploited in the wild, in CISA KEV since 2026-07-10). Affects: iCagenda — events/calendar extension (component) for Joomla. Tags: joomla, icagenda, file-upload, rce, cwe-434, unauthenticated, remote, kev, cms, php, access-control-bypass.</description><category>web</category><category>Critical</category><category>joomla</category><category>icagenda</category><category>file-upload</category><category>rce</category><category>cwe-434</category><category>unauthenticated</category><category>remote</category><category>kev</category><category>cms</category><category>php</category><category>access-control-bypass</category></item><item><title>SP LMS PHP Object Injection → Unauthenticated RCE (CVE-2026-48909)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48909-sp-lms-joomla-phpobjectinjection-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-48909-sp-lms-joomla-phpobjectinjection-rce/</guid><description>Critical severity (CVSS 9.5) — web · CVE-2026-48909 (GHSA-gf8c-xmwj-whrh). Status: PoC. Affects: JoomShaper SP LMS (com_splms) Joomla Learning Management System extension. Tags: joomla, sp-lms, com_splms, php-object-injection, cwe-502, deserialization, unauthenticated-rce, gadget-chain.</description><category>web</category><category>Critical</category><category>joomla</category><category>sp-lms</category><category>com_splms</category><category>php-object-injection</category><category>cwe-502</category><category>deserialization</category><category>unauthenticated-rce</category><category>gadget-chain</category></item><item><title>Joomla Page Builder CK Unauthenticated Arbitrary File Upload RCE — CVE-2026-56290</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-56290-joomla-pagebuilderck-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-56290-joomla-pagebuilderck-rce/</guid><description>Critical severity (CVSS 9.8) — web · CVE-2026-56290. Status: PoC. Affects: Page Builder CK (com_pagebuilderck) — Joomla extension. Tags: joomla, page-builder-ck, com_pagebuilderck, file-upload, unauth-rce, csrf, cms.</description><category>web</category><category>Critical</category><category>joomla</category><category>page-builder-ck</category><category>com_pagebuilderck</category><category>file-upload</category><category>unauth-rce</category><category>csrf</category><category>cms</category></item><item><title>Joomla Novarain Framework (nrframework) Unauthenticated Arbitrary File Inclusion — CVE-2026-21627</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21627-joomla-nrframework-rce/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-21627-joomla-nrframework-rce/</guid><description>Critical severity (CVSS 9.5) — web · CVE-2026-21627. Status: Weaponized. Affects: plg_system_nrframework (Tassos/Novarain Framework) Joomla plugin, bundled with Convert Forms, Engage Box, Google Structured Data, and other Tassos.gr extensions. Tags: joomla, nrframework, file-inclusion, unauthenticated, arbitrary-file-upload, arbitrary-file-delete, php, cms.</description><category>web</category><category>Critical</category><category>joomla</category><category>nrframework</category><category>file-inclusion</category><category>unauthenticated</category><category>arbitrary-file-upload</category><category>arbitrary-file-delete</category><category>php</category><category>cms</category></item><item><title>JoomCCK Unauthenticated SQL Injection via `tags.save` (CVE-2026-49048)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49048-joomcck-sqli/</link><pubDate>Sun, 05 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-05_cve-2026-49048-joomcck-sqli/</guid><description>Critical severity (CVSS 8.7) — web · CVE-2026-49048 (Advisory ID JOOMCCK-2026-001). Status: PoC. Affects: JoomCCK (com_joomcck) — Content Construction Kit extension for Joomla, by JoomCoder. Tags: joomla, joomcck, com_joomcck, sql-injection, cwe-89, missing-authorization, cwe-862, unauthenticated, blind-sqli, union-based.</description><category>web</category><category>Critical</category><category>joomla</category><category>joomcck</category><category>com_joomcck</category><category>sql-injection</category><category>cwe-89</category><category>missing-authorization</category><category>cwe-862</category><category>unauthenticated</category><category>blind-sqli</category><category>union-based</category></item><item><title>Unauthenticated RCE in Joomla Content Editor (JCE) Profile Import (CVE-2026-48907)</title><link>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-48907-joomla-jce-unauth-rce/</link><pubDate>Wed, 01 Jul 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-07-01_cve-2026-48907-joomla-jce-unauth-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48907. Status: Weaponized. Affects: Joomla Content Editor (JCE) extension by Widget Factory. Tags: RCE, unauthenticated, Joomla, JCE, CMS, access-control, webshell, php-webshell, file-upload, CISA-KEV, active-exploitation.</description><category>web</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>Joomla</category><category>JCE</category><category>CMS</category><category>access-control</category><category>webshell</category><category>php-webshell</category><category>file-upload</category><category>CISA-KEV</category><category>active-exploitation</category></item><item><title>SP Page Builder (Joomla) Unauthenticated File Upload RCE (CVE-2026-48908)</title><link>https://poc.intelseclab.com/pocs/web/2026-06-30_cve-2026-48908-sp-page-builder-joomla-rce/</link><pubDate>Tue, 30 Jun 2026 00:00:00 +0000</pubDate><guid>https://poc.intelseclab.com/pocs/web/2026-06-30_cve-2026-48908-sp-page-builder-joomla-rce/</guid><description>Critical severity (CVSS 10) — web · CVE-2026-48908 (GHSA-8fwr-8fxr-8v2p). Status: Weaponized — public PoC with mass-scan support, added to CISA KEV 2026-07-07, confirmed active in-the-wild exploitation. Affects: SP Page Builder extension for Joomla (joomshaper.net). Tags: RCE, unauthenticated, file-upload, PHP-webshell, Joomla, CMS, access-control, Python, CVSS-10, kev, backdoor, cwe-434.</description><category>web</category><category>Critical</category><category>RCE</category><category>unauthenticated</category><category>file-upload</category><category>PHP-webshell</category><category>Joomla</category><category>CMS</category><category>access-control</category><category>Python</category><category>CVSS-10</category><category>kev</category><category>backdoor</category><category>cwe-434</category></item></channel></rss>