CVE-2026-65883: Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0
Published Jul 29, 2026
·Updated
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
Affected Software
2 affected components
Joomla Extension - Aimy Captcha-Less Form Guard>=18.0<=20.0
aimy-extensions Aimy Captcha-less Form Guard Joomla\!>=18.0<=20.0
Event History
Jul 29, 2026
CVE Published
via MITRE·09:34 AM
Data Sourced
via MITRE·09:34 AM
DescriptionWeakness
Data Sourced
via NVD·11:16 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2026-65883?
CVE-2026-65883 has a critical severity rating of 10.
2
How do I fix CVE-2026-65883?
To fix CVE-2026-65883, update the Aimy Captcha-Less Form Guard extension to version 20.0 or later.
3
What type of vulnerability is CVE-2026-65883?
CVE-2026-65883 is a remote code execution vulnerability caused by PHP object injection.
4
Which software is affected by CVE-2026-65883?
CVE-2026-65883 affects the Joomla Extension Aimy Captcha-Less Form Guard versions 18.0 to 20.0.
5
What is the impact of exploiting CVE-2026-65883?
Exploiting CVE-2026-65883 allows attackers to execute arbitrary PHP code on the server.