← Back to browse · API

CVE-2026-65883

Severity
CRITICAL
CVSS
9.8
Published
2026-07-29
Modified
2026-08-05
First seen
2026-08-05
Aliases
-
Products
aimy-extensions:aimy_captcha-less_form_guard
Sources
nvd CVE-2026-65883

Description

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

References