mySites.guru - WordPress & Joomla Site Manager
Someone told me Joomla extensions were more secure than WordPress plugins. They are not, it is just that nobody looks as hard, because there is bounty money in WordPress and none in Joomla. So we went looking. In a month, mySites.guru found and responsibly reported twelve separate security vulnerabilities in widely used Joomla extensions, and reported every one privately to its vendor first. Most were critical: an anonymous visitor could upload and run code, or read your whole database, with no login. The affected extensions include PageBuilder CK, Balbooa Forms, RSFiles!, Phoca Download, AcyMailing, SP Page Builder, iCagenda and the Helix template frameworks. Nine are already patched, three more are still in active disclosure and redacted until their vendors ship fixes. If you run Joomla, update these extensions now. mySites.guru already flags every connected site still on a vulnerable version. Full roundup on the blog. https://mysites.guru/blog/a-month-of-joomla-security-disclosures/?utm_source=facebook&utm_medium=social