CVE-2026-65883

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

  • Published Jul 29, 2026
  • CVSS 10.0 critical
  • 0.8% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-65883 at the National Vulnerability Database