VERKLAREN niet mogelijk voor zoekopdracht: UPDATE `hmclx_extensions`
SET `params` = '{\"htp_shield\":{\"site_path\":\"\",\"sef_rules\":1,\"api_router\":1,\"api_mode\":\"route\",\"fastcgi_auth\":1,\"apache_options\":1,\"follow_symlink\":0,\"force_https\":1,\"www_mode\":0,\"canonical_host\":\"\",\"h_frame\":1,\"h_nosniff\":1,\"h_referrer\":\"strict-origin-when-cross-origin\",\"h_poweredby\":1,\"h_hsts\":0,\"h_hsts_sub\":0,\"h_coop\":0,\"h_permissions\":0,\"f_query\":1,\"f_rfi\":1,\"f_methods\":1,\"f_wpnoise\":1,\"htaccess_external\":0,\"shield_autoheal\":1,\"shield_autoheal_last\":0,\"mig_selfon_2415\":1,\"guard_dismissed\":0,\"x_shield\":1,\"x_sigs_off\":[],\"defs_version\":\"2026-07-15.9ac386\",\"mal_whitelist\":[],\"u_harden\":1,\"u_dirs\":[\"images\",\"media\"],\"emergency_lock\":0,\"notify_email\":\"pch.info@dubbelbit.nl\",\"notify_reminder_days\":14,\"unsub_secret\":\"knIOkiU01E3ceU0YZZ8ARjTQkWuTbqXAfktb1qjg6K0\",\"unsub_base\":\"https:\\/\\/www.efitec.nl\\/\",\"site_fp\":\"6d83c72d155aaa19f87ab9edd8cf222657b5b548\",\"swarm_contrib_id\":\"\",\"swarm_acked\":[],\"watch_manifest\":{\".htaccess\":\"dcb97f95087f2bdb336d0ffdcc300371ca6c4c51\",\"administrator\\/.htaccess\":\"2a00152a7d76a1d4a9444edf477c7404821a8b08\",\"images\\/.htaccess\":\"69714eb0929213f686d66baa144fceefbb395f8f\",\"media\\/.htaccess\":\"69714eb0929213f686d66baa144fceefbb395f8f\"},\"core_manifest\":{\"index.php\":\"2f1b60fc565276ae146bea9aaeadec93fb4dc87c\",\"administrator\\/index.php\":\"7078c5d7b2181900c509c93302f324e2dae228bf\"},\"core_jversion\":\"3.10.12\",\"accounts_watch\":1,\"account_baseline\":{\"613\":{\"id\":613,\"username\":\"admin\",\"email\":\"pch.info@dubbelbit.nl\",\"phash\":\"6300584d05e69c7f07ba2fb51a2f5ade41aeedd4\",\"block\":0,\"lastvisit\":\"2026-07-15 10:54:36\",\"pneeds\":0},\"800\":{\"id\":800,\"username\":\"dubbelbit\",\"email\":\"info@dubbelbit.nl\",\"phash\":\"081a5bae87c5a349a57ac9416a5157be4b8f95d5\",\"block\":0,\"lastvisit\":\"2025-11-06 17:15:16\",\"pneeds\":0}},\"admin_whitelist\":[],\"helix_ignore\":[],\"seo_watch\":1,\"compat_guard\":1,\"seo_cloaking_auto\":0,\"seo_whitelist\":[],\"seo_topic_ack\":[],\"seo_baseline\":{\"title\":\"Home\",\"out_domains\":{\"www.facebook.com\":1,\"nl.pinterest.com\":1,\"www.youtube.com\":1,\"www.s-bb.nl\":1,\"nieuw.efitec.nl\":1,\"xdebug.org\":1},\"shingles\":{\"511079512\":1,\"2918310184\":1,\"155886152\":1,\"3160688592\":1,\"3485062088\":1,\"585239104\":1,\"3828873704\":1,\"4087449296\":1,\"3631890208\":1,\"2453473432\":1,\"352088384\":1,\"1507055824\":1,\"1387258184\":1,\"96078016\":1,\"4120744744\":1,\"884599352\":1,\"148068952\":1,\"2322729328\":1,\"1647395640\":1,\"550572240\":1,\"2804985368\":1,\"2665301464\":1,\"3371643872\":1,\"1999195856\":1,\"412108984\":1,\"268508784\":1,\"3442173200\":1,\"2599037872\":1,\"4081499304\":1,\"187337984\":1,\"362962264\":1,\"2094558736\":1,\"2787016200\":1,\"1792673952\":1,\"760828480\":1,\"3190343216\":1,\"2235320368\":1,\"2015524016\":1,\"148784336\":1,\"1233375328\":1,\"3067298240\":1,\"2030274208\":1,\"2177272832\":1,\"3545206312\":1,\"1552018832\":1,\"344452216\":1,\"202494824\":1,\"1366336928\":1,\"2554787144\":1,\"1848356288\":1,\"3951814824\":1,\"190450920\":1,\"982788704\":1,\"3214585776\":1,\"1332842344\":1,\"1438779232\":1,\"1993946344\":1,\"140539032\":1,\"1152820144\":1,\"1473178688\":1,\"283455248\":1,\"2717990208\":1,\"829495128\":1,\"3748426760\":1,\"3087180272\":1,\"244570696\":1,\"1779663400\":1,\"3007757520\":1,\"3011879432\":1,\"1946413488\":1,\"2106478384\":1,\"3859231160\":1,\"2361006672\":1,\"682230128\":1,\"1366868840\":1,\"2799752896\":1,\"3407503488\":1,\"3712801368\":1,\"4113024016\":1,\"2056195792\":1,\"51760832\":1,\"211001480\":1,\"1209613064\":1,\"1950179312\":1,\"39928272\":1,\"2520740096\":1,\"810676984\":1,\"3946537872\":1,\"1061088320\":1,\"924937024\":1,\"2981285080\":1,\"2275428680\":1,\"1094268640\":1,\"1158834928\":1,\"1300147528\":1,\"4096226856\":1,\"1925217168\":1,\"4239054088\":1,\"2797136096\":1,\"3557110600\":1,\"4041208904\":1,\"1327249520\":1,\"1607673584\":1,\"4007425464\":1,\"2632851624\":1,\"1123389784\":1,\"2693581640\":1,\"3409153800\":1,\"3008275536\":1,\"1337666672\":1,\"4176326200\":1,\"2991890336\":1,\"3462925544\":1,\"2964742568\":1,\"1345094056\":1,\"2907109104\":1,\"1561660688\":1,\"1048480240\":1,\"1489547928\":1,\"3106242904\":1,\"1806222752\":1,\"254204696\":1,\"2776431456\":1,\"507422944\":1,\"4101744904\":1,\"482057768\":1,\"942566752\":1,\"3196827536\":1,\"2263293544\":1,\"4102387360\":1,\"588054000\":1,\"965466024\":1,\"2011588072\":1,\"1559046784\":1,\"4007417480\":1,\"7730296\":1,\"1458451704\":1,\"2911589176\":1,\"454621680\":1,\"1251844592\":1,\"1416323816\":1,\"1029458376\":1,\"1792465472\":1,\"4123225216\":1,\"670221008\":1,\"2571777288\":1,\"3627078176\":1,\"293222816\":1,\"281163600\":1,\"2508087208\":1,\"848595304\":1,\"3107900104\":1,\"2589595704\":1,\"2034508136\":1,\"1977429088\":1,\"2584638584\":1,\"2493542936\":1,\"1223539912\":1,\"2846665840\":1,\"1613823168\":1,\"39764600\":1,\"4261163824\":1,\"3766837440\":1,\"1856123928\":1,\"376102376\":1,\"3931301920\":1,\"2256249280\":1,\"1618392856\":1,\"1672646016\":1,\"2709313920\":1,\"444641888\":1,\"1467316144\":1,\"4217705304\":1,\"716719120\":1,\"4096007544\":1,\"1531644320\":1,\"401106408\":1,\"1421905088\":1,\"3294019280\":1,\"933003528\":1,\"2230427152\":1,\"1208455864\":1,\"2025534160\":1,\"1408784776\":1,\"2685059296\":1,\"3489792648\":1,\"1615724560\":1,\"3733711632\":1,\"3792461240\":1,\"2550915448\":1,\"1067862528\":1,\"1935561680\":1,\"1711020488\":1,\"1911606592\":1,\"3230085528\":1,\"2552993816\":1,\"2123798152\":1,\"3761658400\":1,\"4124423392\":1,\"1153004272\":1,\"796890520\":1,\"1247028480\":1,\"958748368\":1,\"1744512424\":1,\"647816080\":1,\"743882928\":1,\"3538140264\":1,\"2706907200\":1,\"4109595712\":1,\"4001889160\":1,\"2713592576\":1,\"650342624\":1,\"109843936\":1,\"3303788176\":1,\"3393712720\":1,\"385269736\":1,\"2772452800\":1,\"10795160\":1,\"3652684152\":1,\"1345583752\":1,\"4138023008\":1,\"1630734352\":1,\"1587613576\":1,\"1950652592\":1,\"2777296976\":1,\"2621186584\":1,\"36106456\":1,\"2825573424\":1,\"303059736\":1,\"1368990104\":1,\"335870296\":1,\"947878136\":1,\"885775072\":1,\"2836090264\":1,\"1479167544\":1,\"3195444184\":1,\"1373515616\":1,\"2703441304\":1,\"2999798000\":1,\"2450256208\":1,\"3679148440\":1,\"4128820280\":1,\"481509568\":1,\"1827743704\":1,\"775113328\":1,\"3226643448\":1,\"3914545768\":1,\"3485632672\":1,\"1455493656\":1,\"3040222736\":1,\"1738075592\":1,\"3987514200\":1,\"428036792\":1,\"2710735120\":1,\"3436957576\":1,\"3230827720\":1,\"1002378832\":1,\"477165832\":1,\"1378722152\":1,\"2798472384\":1,\"272556984\":1,\"1915969656\":1,\"351010464\":1,\"2168780672\":1,\"3455691560\":1,\"1003486592\":1,\"3101468488\":1,\"2826036216\":1,\"420540632\":1,\"4203005848\":1,\"4015778440\":1,\"1216866856\":1,\"796841416\":1,\"1859028960\":1,\"2694091560\":1,\"2607914576\":1,\"957468880\":1,\"2958138832\":1,\"4227793112\":1,\"2834052552\":1,\"3439897368\":1,\"2144818552\":1,\"3130333816\":1,\"3591606896\":1,\"1894249248\":1,\"4188555200\":1,\"245520800\":1,\"1682089672\":1,\"9149544\":1,\"3226699984\":1,\"1372800744\":1,\"2964205104\":1,\"722285192\":1,\"2467453096\":1,\"1116378504\":1,\"3895415872\":1,\"1253935208\":1,\"528756504\":1,\"2284709784\":1,\"802473640\":1,\"3733678920\":1,\"361847392\":1,\"1232831160\":1,\"144058216\":1,\"1338885880\":1,\"992984272\":1,\"3773773072\":1,\"4182600\":1,\"2502992360\":1,\"4070217592\":1,\"714945560\":1,\"4220390656\":1,\"821879880\":1,\"3181784208\":1,\"2359186248\":1,\"1534907152\":1,\"1530568368\":1,\"3978930832\":1,\"4141876912\":1,\"3134899488\":1,\"1235858440\":1,\"810201200\":1,\"3783382792\":1,\"3515040152\":1,\"1393803552\":1,\"967317216\":1,\"3068177256\":1,\"798171424\":1,\"3843014608\":1,\"610676112\":1,\"2514595056\":1,\"3925377248\":1,\"3302495736\":1,\"3781864704\":1,\"3031336392\":1,\"2021863136\":1,\"3028956464\":1,\"133926968\":1,\"3039953848\":1,\"1385104704\":1,\"4245224744\":1,\"4290332968\":1,\"2274655504\":1,\"1645581528\":1,\"2669455816\":1,\"3722712864\":1,\"1646278032\":1,\"2080430464\":1,\"1286501976\":1,\"1591713568\":1,\"1088809128\":1,\"3634194248\":1,\"4152895848\":1,\"3676099064\":1,\"3585114784\":1,\"3235297640\":1,\"1552428824\":1,\"1872388720\":1,\"3499880416\":1,\"4008708616\":1,\"3640799032\":1,\"252019184\":1,\"673687856\":1,\"1020035096\":1,\"1477984416\":1,\"798794864\":1,\"3895830512\":1,\"3877253568\":1,\"3725099576\":1,\"2100351152\":1,\"1558271616\":1,\"2474987096\":1,\"3543193024\":1,\"73942424\":1,\"13272208\":1,\"1943482168\":1,\"1547675656\":1,\"1718305248\":1,\"1732106904\":1,\"1643112200\":1,\"2756430048\":1,\"3580986048\":1},\"redirect_to\":\"\",\"ts\":1787924003},\"seo_overview_ts\":1787924002,\"seo_overview_finding\":[],\"core_overview_ts\":1784128054,\"core_overview_finding\":[],\"plugin_initialized\":1,\"quickicon_initialized\":1,\"autosecure\":0,\"autosecure_last\":0,\"tmp_autoclean\":0,\"tmp_keep\":[],\"autoupdate_notify\":0,\"autoupdate_ext\":1,\"autoupdate_all\":0,\"autoupdate_self\":1,\"autoupdate_manual\":0,\"autoupdate_mail_success\":0,\"autoupdate_include\":[],\"autoupdate_keep\":1,\"autoupdate_interval\":86400,\"autoupdate_schedule\":\"daily\",\"autoupdate_hour\":21,\"autoupdate_weekday\":5,\"autoupdate_grace\":3,\"autoupdate_malscan\":1,\"autoupdate_skip_major\":0,\"keep_update_sites\":1,\"keep_update_sites_except\":[],\"s_php\":1,\"s_types\":1,\"s_ext\":\"7z,avif,bmp,br,css,csv,doc,docx,eot,geojson,gif,gml,gpx,gz,htm,html,ico,ics,jp2,jpe,jpeg,jpg,js,json,kml,kmz,m4a,m4v,map,mjs,mov,mp3,mp4,mpeg,mpg,odp,ods,odt,oga,ogg,ogv,opus,otf,pdf,png,ppt,pptx,rar,rtf,svg,svgz,tif,tiff,ttf,txt,vtt,wasm,wav,webm,webmanifest,webp,woff,woff2,xls,xlsx,xml,xsl,zip\",\"s_files\":[\"administrator\\/components\\/com_akeeba\\/restore.php\",\"administrator\\/components\\/com_akeebabackup\\/restore.php\"],\"s_dirs_php\":[\"plugins\\/system\\/bfnetwork\"],\"s_dirs_static\":[],\"allow_paths\":[],\"s_dotfiles\":1,\"s_wellknown\":1,\"s_sensitive\":1,\"s_manifests\":0,\"s_sysdirs\":1,\"s_sysdirs_list\":[\"administrator\\/cache\",\"administrator\\/logs\",\"cache\",\"cli\",\"log\",\"logs\",\"tmp\"],\"p_compress\":1,\"p_precomp\":0,\"p_expires\":1,\"p_etag\":0,\"custom_top\":\"\",\"custom_bottom\":\"\",\"file_sha1\":\"dcb97f95087f2bdb336d0ffdcc300371ca6c4c51\",\"last_written\":\"2026-07-15 17:20:03\",\"last_test\":{\"checks\":[{\"label\":\"Home page reachable\",\"url\":\"https:\\/\\/www.efitec.nl\\/\",\"status\":200,\"ok\":true,\"note\":\"\"},{\"label\":\"Backend reachable (401 = password protection active)\",\"url\":\"https:\\/\\/www.efitec.nl\\/administrator\\/index.php\",\"status\":401,\"ok\":true,\"note\":\"\"},{\"label\":\"PHP shield active (test call is rejected with 403)\",\"url\":\"https:\\/\\/www.efitec.nl\\/htpx-canary-fbfbe897.php\\/htp\",\"status\":403,\"ok\":true,\"note\":\"\"},{\"label\":\"configuration.php blocked\",\"url\":\"https:\\/\\/www.efitec.nl\\/configuration.php\",\"status\":403,\"ok\":true,\"note\":\"\"}],\"regression\":false,\"reason\":\"\",\"time\":\"2026-07-15 15:20:03\"},\"guard_dir\":\"\",\"guard_recover\":\"263c210ee005a46813c42d75dd82d7144cb9b918b4356d8c60a8f9225963fe48\",\"welcome_sent\":1,\"welcome_green_since\":0,\"jed_review_ack\":\"\",\"jed_mail_last\":0,\"htaccess_cap\":[]},\"htp_defs\":{\"schema\":1,\"version\":\"2026-08-27.e17bd0\",\"signatures\":[{\"id\":\"jce-profiles-import\",\"label\":\"JCE Profil-Import (CVE-2026-48907)\",\"label_en\":\"JCE profile import (CVE-2026-48907)\",\"desc\":\"Unauthentifizierter Profil-Import im JCE-Editor - Beginn der aktuellen RCE-Kette (schaltet PHP-Uploads frei). Kein legitimer Frontend-Aufruf.\",\"desc_en\":\"Unauthenticated profile import in the JCE editor - start of the current RCE chain (enables PHP uploads). No legitimate frontend call.\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*task=profiles\\\\.import)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"jce-rpc-upload\",\"label\":\"JCE Webshell-Upload via plugin.rpc (CVE-2026-48907)\",\"label_en\":\"JCE webshell upload via plugin.rpc (CVE-2026-48907)\",\"desc\":\"Datei-Upload \\u00fcber den JCE-Dateibrowser (plugin.rpc, method=upload). Greift nur im Frontend; eingeloggte Autoren (legitimer Editor-Upload) bleiben unber\\u00fchrt.\",\"desc_en\":\"File upload via the JCE file browser (plugin.rpc, method=upload). Applies only on the frontend; logged-in authors (legitimate editor upload) are unaffected.\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*task=plugin\\\\.rpc)(?=.*method=upload)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":null},{\"id\":\"jce-imgmanager\",\"label\":\"JCE Image Manager (Alt-Exploit)\",\"label_en\":\"JCE Image Manager (legacy exploit)\",\"desc\":\"Klassischer unauthentifizierter Datei-Upload \\u00fcber den JCE-Bildmanager (sehr alte JCE-Versionen).\",\"desc_en\":\"Classic unauthenticated file upload via the JCE image manager (very old JCE versions).\",\"default\":1,\"qs\":\"(?=.*option=com_jce)(?=.*plugin=imgmanager)(?=.*method=form)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":null},{\"id\":\"novarain-nrframework\",\"label\":\"Novarain \\/ Tassos Framework (com_ajax include)\",\"label_en\":\"Novarain \\/ Tassos Framework (com_ajax include)\",\"desc\":\"CVE-2026-21627: unauthentifizierte PHP-Datei-Einbindung \\u00fcber plg_system_nrframework via com_ajax (task=include).\",\"desc_en\":\"CVE-2026-21627: unauthenticated PHP file inclusion via plg_system_nrframework through com_ajax (task=include).\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*nrframework)(?=.*task=include)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"astroid-ajax\",\"label\":\"Astroid Framework (AJAX-Endpunkt)\",\"label_en\":\"Astroid Framework (AJAX endpoint)\",\"desc\":\"CVE-2026-21628: ungepr\\u00fcfter Astroid-AJAX-Endpunkt (Upload\\/Installation). Coarse-Match auf com_ajax + astroid.\",\"desc_en\":\"CVE-2026-21628: unchecked Astroid AJAX endpoint (upload\\/installation). Coarse match on com_ajax + astroid.\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*(plugin|template|view)=astroid)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"helix3-ajax\",\"label\":\"Helix3 (JoomShaper): unauth. com_ajax-Handler (Datei schreiben\\/l\\u00f6schen)\",\"label_en\":\"Helix3 (JoomShaper): unauth com_ajax handler (file write\\/delete)\",\"desc\":\"Helix3 < 3.1.1: der Ajax-Handler onAjaxHelix3 pr\\u00fcfte weder Login noch Rechte. Trifft gezielt die gef\\u00e4hrlichen Unauth-Aktionen im POST-Body: save (Layout-JSON ins aktive Template schreiben), remove (Datei l\\u00f6schen via Path-Traversal), import (Template-Style-Settings \\u00fcberschreiben) sowie upload_image\\/remove_image\\/updateFonts. Legitime Gast-Aktionen (voting, load) und eingeloggte Template-Nutzung \",\"desc_en\":\"Helix3 < 3.1.1: the onAjaxHelix3 ajax handler checked neither login nor permission. Targets the dangerous unauth POST-body actions: save (write layout JSON into the active template), remove (delete a file via path traversal), import (overwrite template style settings) plus upload_image\\/remove_image\\/updateFonts. Legitimate guest actions (voting, load) and logged-in template use are unaffected. Fix:\",\"default\":1,\"qs\":\"data(?:\\\\[|%5b)action(?:\\\\]|%5d)=(?:save|remove|import|updatefonts)|action=(?:upload_image|remove_image)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"helix3-comajax\",\"label\":\"Helix3 (JoomShaper): unauth. com_ajax-Dispatcher (Datei-Write\\/Delete, Style-Injektion)\",\"label_en\":\"Helix3 (JoomShaper): unauth com_ajax dispatcher (file write\\/delete, style injection)\",\"desc\":\"Helix3 < 3.1.1: der Front-Dispatcher (option=com_ajax mit plugin=helix3) rief onAjaxHelix3 VOR jeder Token-\\/Rechtepr\\u00fcfung auf - unauthentifiziert save\\/import\\/remove\\/resetLayout\\/updateFonts\\/fontVariants (Datei-Schreiben, Path-Traversal-L\\u00f6schen, Template-Style-Injektion, Stored XSS). Blockt jeden GAST-Aufruf dieses Dispatchers im Frontend (Defense-in-Depth, f\\u00e4ngt auch laufende Scans) - erg\\u00e4nzt d\",\"desc_en\":\"Helix3 < 3.1.1: the front-end dispatcher (option=com_ajax with plugin=helix3) invoked onAjaxHelix3 BEFORE any token\\/permission check - unauthenticated save\\/import\\/remove\\/resetLayout\\/updateFonts\\/fontVariants (file write, path-traversal delete, template style injection, stored XSS). Blocks every GUEST call of this dispatcher on the front end (defense in depth, also catches ongoing scans) - complemen\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*plugin=helix3\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"helixultimate-comajax\",\"label\":\"Helix Ultimate (JoomShaper): unauth. com_ajax-Dispatcher (Men\\u00fc-Write\\/Datei\\/Export)\",\"label_en\":\"Helix Ultimate (JoomShaper): unauth com_ajax dispatcher (menu write\\/file\\/export)\",\"desc\":\"Helix Ultimate < 2.2.7: der com_ajax-Handler onAjaxHelixultimate (option=com_ajax mit plugin=helixultimate, Action im task-Param) lief VOR jeder Login-\\/Rechtepr\\u00fcfung - ein anonymer Angreifer konnte in die Men\\u00fc-Einstellungen schreiben (Stored XSS bis in die Admin-Sitzung), Dateien per Path-Traversal beliebig l\\u00f6schen, einen Open Redirect ausl\\u00f6sen und das Template ungesch\\u00fctzt exportieren. Blockt\",\"desc_en\":\"Helix Ultimate < 2.2.7: the com_ajax handler onAjaxHelixultimate (option=com_ajax with plugin=helixultimate, action in the task param) ran BEFORE any login\\/permission check - an anonymous attacker could write into the menu settings (stored XSS reaching the admin session), delete files anywhere via path traversal, trigger an open redirect and export the template unprotected. Blocks every GUEST call\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*plugin=helixultimate\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"comajax-include\",\"label\":\"com_ajax: Datei-Einbindung (generisch)\",\"label_en\":\"com_ajax: file inclusion (generic)\",\"desc\":\"F\\u00e4ngt unbekannte LFI-L\\u00fccken derselben Klasse ab: com_ajax mit task=include\\/require. Frontend.\",\"desc_en\":\"Catches unknown LFI holes of the same class: com_ajax with task=include\\/require. Frontend.\",\"default\":1,\"qs\":\"(?=.*option=com_ajax)(?=.*task=(include|require)(_once)?)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"sppagebuilder-uploadicon\",\"label\":\"SP Page Builder: unauthentifizierter Icon-Upload (RCE)\",\"label_en\":\"SP Page Builder: unauthenticated icon upload (RCE)\",\"desc\":\"Zero-Day in SP Page Builder bis 6.6.1: der asset-Controller (task=asset.uploadCustomIcon) hatte keinerlei Zugriffs-\\/Login-Pr\\u00fcfung - unauthentifizierter Datei-Upload nach \\/media\\/com_sppagebuilder\\/assets\\/iconfont\\/ - RCE. Nur Mini-WAF (G\\u00e4ste), da eingeloggte Builder den Endpunkt legitim nutzen.\",\"desc_en\":\"Zero-day in SP Page Builder up to 6.6.1: the asset controller (task=asset.uploadCustomIcon) had no access\\/login check - unauthenticated file upload to \\/media\\/com_sppagebuilder\\/assets\\/iconfont\\/ - RCE. Mini-WAF only (guests), since logged-in builders use the endpoint legitimately.\",\"default\":1,\"qs\":\"(?=.*option=com_sppagebuilder)(?=.*task=asset\\\\.uploadCustomIcon)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":null},{\"id\":\"dpcalendar-createdby-sqli\",\"label\":\"DPCalendar: unauth. SQL-Injection (Autor-Filter)\",\"label_en\":\"DPCalendar: unauth SQL injection (author filter)\",\"desc\":\"DPCalendar Blind-SQLi (Joomla 4.4-6 < 10.11.2, J3 < 8.19.4): der Frontend-Autor-Filter filter_created_by (option=com_dpcalendar, view=events) floss in skalarer Form ungecastet in a.created_by IN (...) - anonymes Auslesen beliebiger DB-Tabellen (nur lesend). Blockt Gast-Anfragen, deren filter_created_by kein reiner Integer ist (legitim = Autor-IDs\\/Ziffern) -> FP-frei. Fix 10.11.2 \\/ 8.19.4.\",\"desc_en\":\"DPCalendar blind SQLi (Joomla 4.4-6 < 10.11.2, J3 < 8.19.4): the front-end author filter filter_created_by (option=com_dpcalendar, view=events) flowed uncast into a.created_by IN (...) in its scalar form - anonymous read of arbitrary DB tables (read-only). Blocks guest requests whose filter_created_by is not a pure integer (legit = author IDs\\/digits) -> FP-free. Fix 10.11.2 \\/ 8.19.4.\",\"default\":1,\"qs\":\"(?=.*option=com_dpcalendar)(?=.*filter_created_by=[0-9,]*[^0-9,&])\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_dpcalendar\"},{\"id\":\"acym-entityselect-sqli\",\"label\":\"AcyMailing: unauth. SQL-Injection (Entity-Select Spaltenliste)\",\"label_en\":\"AcyMailing: unauth SQL injection (entity-select column list)\",\"desc\":\"CVE-2026-56292 (AcyMailing 6.0.0-10.11.0): der Frontend-Endpunkt EntitySelectController::loadEntityFront (option=com_acym, task=loadEntityFront) nahm die Request-Parameter columns\\/join_table ungeprueft in die SELECT-Spaltenliste von UserClass::getMatchingElements auf - ein anonymer Besucher konnte per Subquery beliebige DB-Tabellen (inkl. Passwort-Hashes) auslesen. Blockt GAST-Aufrufe dieses Tasks\",\"desc_en\":\"CVE-2026-56292 (AcyMailing 6.0.0-10.11.0): the front-end endpoint EntitySelectController::loadEntityFront (option=com_acym, task=loadEntityFront) placed the request parameters columns\\/join_table unchecked into the SELECT column list of UserClass::getMatchingElements - an anonymous visitor could read arbitrary DB tables (incl. password hashes) via a subquery. Blocks GUEST calls of this task whose c\",\"default\":1,\"qs\":\"(?=.*option=com_acym)(?=.*task=loadEntityFront)(?=.*(?:columns|join_table|join)=[^&]*(?:\\\\(|%28|%2528|\\\\s|%20|\\\\+))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_acym\"},{\"id\":\"quix-article-sqli\",\"label\":\"Quix Page Builder: unauth. SQL-Injection (Einzel-Artikel-AJAX)\",\"label_en\":\"Quix Page Builder: unauth SQL injection (single-article AJAX)\",\"desc\":\"Quix (ThemeXpert, Free UND Pro) bis 6.2.0, inkl. der 5.x-Reihe: der oeffentliche AJAX-Endpunkt (option=com_quix, task=ajax, element=joomla-article) ruft QuixJoomlaArticleElement::getAjax() ohne Login-\\/Token-\\/Lizenz-Pruefung; die Artikel-ID kommt base64-kodiert im data-Parameter und wird in articleExist() UNGECASTET in die DB-Query konkateniert -> unauthentifizierte, fehler-basierte SQL-Injection (\",\"desc_en\":\"Quix (ThemeXpert, Free AND Pro) up to 6.2.0, incl. the 5.x line: the public AJAX endpoint (option=com_quix, task=ajax, element=joomla-article) calls QuixJoomlaArticleElement::getAjax() with no login\\/token\\/license check; the article id arrives base64-encoded in the data parameter and is concatenated UNCAST into the DB query in articleExist() -> unauthenticated error-based SQL injection (CVSS 8.7). \",\"default\":1,\"qs\":\"(?=.*option=com_quix)(?=.*task=ajax\\\\b)(?=.*element=joomla-article\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_quix\"},{\"id\":\"phocacart-filter-sqli\",\"label\":\"Phoca Cart: unauth. SQL-Injection (Produktfilter a\\/s)\",\"label_en\":\"Phoca Cart: unauth SQL injection (product filter a\\/s)\",\"desc\":\"CVE-2026-74251 (CVSS 9.3, Phoca Cart J5-Reihe < 5.2.4 \\/ J6-Reihe < 6.1.7; 3.x und 4.x komplett): der \\u00f6ffentliche Produktfilter (option=com_phocacart) liest die Array-Parameter a (Attribute) und s (Spezifikationen) und h\\u00e4ngt ihre Werte UNGEQUOTET in die WHERE-Klausel (IN()- bzw. Gleichheits-Bedingung) - auf einer Gast-Seite ohne Login\\/Token -> unauthentifizierte, blinde SQL-Injection (Auslesen de\",\"desc_en\":\"CVE-2026-74251 (CVSS 9.3, Phoca Cart J5 line < 5.2.4 \\/ J6 line < 6.1.7; 3.x and 4.x entirely): the public product filter (option=com_phocacart) reads the array parameters a (attributes) and s (specifications) and appends their values UNQUOTED into the WHERE clause (IN() \\/ equality condition) - on a guest page with no login\\/token -> unauthenticated blind SQL injection (database read). Blocks GUEST \",\"default\":1,\"qs\":\"(?=(?:^|.*&)option=com_phocacart)(?=(?:^|.*&)(?:%20|\\\\+|\\\\s)*(?:a|s)(?:\\\\[|%5b)[^&]*(?:%(?:27|22|5c)|[\\\\x27\\\\x22\\\\x5c]))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_phocacart\"},{\"id\":\"icagenda-calendar-sqli\",\"label\":\"iCagenda: unauth. SQL-Injection (Kalender-Modul \\u00fcber com_ajax)\",\"label_en\":\"iCagenda: unauth SQL injection (calendar module via com_ajax)\",\"desc\":\"CVE-2026-67365 (CVSS 9.2, iCagenda 4.0.0-4.0.11): das Kalender-Modul mod_icagenda_calendar wird \\u00fcber com_ajax (option=com_ajax&module=icagenda_calendar) OHNE Session, Token oder Konto erreicht und haengt einen Request-Parameter ungefiltert in eine SQL-Abfrage - unauthentifizierte SQL-Injection (Datenbank auslesen). Das Kalender-Ajax ist ein LEGITIMES Gast-Feature (Monats-\\/Kategorie-Navigation), d\",\"desc_en\":\"CVE-2026-67365 (CVSS 9.2, iCagenda 4.0.0-4.0.11): the calendar module mod_icagenda_calendar is reached via com_ajax (option=com_ajax&module=icagenda_calendar) with NO session, token or account and appends a request parameter unfiltered into a SQL query - unauthenticated SQL injection (database read). The calendar ajax is a LEGITIMATE guest feature (month\\/category navigation), so this does NOT bloc\",\"default\":1,\"qs\":\"(?=(?:^|.*&)option=com_ajax)(?=(?:^|.*&)module=icagenda_calendar)(?=.*(?:%27|%22|%5c|[\\\\x27\\\\x22\\\\x5c]|\\\\bunion\\\\b[\\\\s+\\/*]*\\\\bselect\\\\b|information_schema|(?:sleep|benchmark|extractvalue|updatexml)(?:%28|\\\\()))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_ajax\"},{\"id\":\"joomcck-tags-sqli\",\"label\":\"JoomCCK: unauth. SQL-Injection (Tag-Verwaltung)\",\"label_en\":\"JoomCCK: unauth SQL injection (tag management)\",\"desc\":\"CVE-2026-49048 (JoomCCK 6.x vor 6.4.1): der Front-End-Task tags.save\\/tags.delete (option=com_joomcck) lief OHNE Token-\\/Login-\\/Rechte-Pruefung und schob den Request-Parameter tag (getString) roh - mit Double-Quote-Ausbruch - in ZWEI aufeinanderfolgende SQL-Statements (Existenz-SELECT + UPDATE). Ein anonymer Besucher konnte die Datenbank auslesen und veraendern (stacked\\/error-based SQLi). Blockt jed\",\"desc_en\":\"CVE-2026-49048 (JoomCCK 6.x before 6.4.1): the front-end task tags.save\\/tags.delete (option=com_joomcck) ran with NO token\\/login\\/permission check and concatenated the request parameter tag (getString) raw - with a double-quote breakout - into TWO consecutive SQL statements (existence SELECT + UPDATE). An anonymous visitor could read and modify the database (stacked\\/error-based SQLi). Blocks every \",\"default\":1,\"qs\":\"(?=.*option=com_joomcck)(?=.*task=tags\\\\.(?:save|delete))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_joomcck\"},{\"id\":\"gridbox-store-register\",\"label\":\"Balbooa Gridbox: unauth. Konto-Erstellung (store.register)\",\"label_en\":\"Balbooa Gridbox: unauth account creation (store.register)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, gemeldet 2026-07-28, Fix in 2.20.2 (29.07.2026). Der Front-End-Task store.register lief OHNE Login\\/Token und legte ein Joomla-Konto mit FREI WAEHLBARER Usergruppe plus sofort gueltiger Session an (unauth Privilege Escalation). Blockt jeden Gast-Aufruf dieses Tasks. Kosten: falls die Site die Gridbox-eigene Frontend-Registrierung nu\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to and incl. 2.20.1 - actively exploited, reported 2026-07-28, fixed in 2.20.2 (29 Jul 2026). The front-end task store.register ran WITHOUT login\\/token and created a Joomla account with an ARBITRARY usergroup plus an immediately valid session (unauth privilege escalation). Blocks every guest call of this task. Cost: if the site uses Gridbox front-end registration (\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=store(\\\\.|%2e)register)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":0,\"trigger\":\"com_gridbox\"},{\"id\":\"gridbox-uploader-showimage-read\",\"label\":\"Balbooa Gridbox: unauth. Datei-Lesen (uploader.showImage)\",\"label_en\":\"Balbooa Gridbox: unauth arbitrary file read (uploader.showImage)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, Fix in 2.20.2 (29.07.2026). Der Front-End-Task uploader.showImage laed ohne Login den Query-Parameter image= und gibt bei Nicht-Bildern die Datei roh aus (fopen+fpassthru) -> unauth Arbitrary File Read, u. a. configuration.php. Trifft JEDE Gridbox-Installation. FP-FREI (2.6.17, Fall prolocore-vigezzo.it: Gridbox laed Bilder als abs\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to and incl. 2.20.1 - actively exploited, fixed in 2.20.2 (29 Jul 2026). The front-end task uploader.showImage reads the query parameter image= without login and, for non-images, dumps the file raw (fopen+fpassthru) -> unauth arbitrary file read incl. configuration.php. Hits EVERY Gridbox install. FP-FREE (2.6.17, case prolocore-vigezzo.it: Gridbox references image\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=uploader(\\\\.|%2e)showImage)(?=.*image=(?:[^&]*(?:\\\\.\\\\.|%2e%2e|%00|php:|php%3a)|(?![^&]*\\\\.(?:jpe?g|png|gif|webp|svg|bmp|ico|avif|tiff?)(?:[&?]|%3f|$))[^&]+))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":\"com_gridbox\"},{\"id\":\"gridbox-uploader-savephoto\",\"label\":\"Balbooa Gridbox: unauth. Datei-Schreiben (uploader.savePhotoEditorImage)\",\"label_en\":\"Balbooa Gridbox: unauth arbitrary file write (uploader.savePhotoEditorImage)\",\"desc\":\"Balbooa Gridbox (com_gridbox) bis inkl. 2.20.1 - aktiv ausgenutzt, Fix in 2.20.2 (29.07.2026). Der Front-End-Task uploader.savePhotoEditorImage schreibt eine beliebige Datei (inkl. .php) in den Webroot; der Zieldateiname liegt im POST-Body (php:\\/\\/input) und ist fuer die .htaccess unsichtbar, und eingeloggte Redakteure nutzen den Endpunkt legitim. Daher waf_only + scope=guest: NUR im Echtzeit-Plugi\",\"desc_en\":\"Balbooa Gridbox (com_gridbox) up to and incl. 2.20.1 - actively exploited, fixed in 2.20.2 (29 Jul 2026). The front-end task uploader.savePhotoEditorImage writes an arbitrary file (incl. .php) into the webroot; the target filename is in the POST body (php:\\/\\/input), invisible to .htaccess, and logged-in editors use the endpoint legitimately. Hence waf_only + scope=guest: enforced ONLY in the real-t\",\"default\":1,\"qs\":\"(?=.*option=com_gridbox)(?=.*task=uploader(\\\\.|%2e)savePhotoEditorImage)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_gridbox\"},{\"id\":\"baforms-signature-rce\",\"label\":\"Balbooa Forms: unauth. RCE (Signature-Feld, CVE-2026-65880)\",\"label_en\":\"Balbooa Forms: unauth RCE (signature field, CVE-2026-65880)\",\"desc\":\"Balbooa Forms (com_baforms) bis inkl. 2.4.2.1 - CVE-2026-65880 (CVSS 10.0), aktiv ausgenutzt, Fix erst 2.4.3. Beim Absenden eines Formulars mit SIGNATURE-Feld (task=form.sendMessage) verwendet FormModel::saveSignature den vom Angreifer im Feld-JSON gelieferten Funktionsnamen dynamisch als aufgerufene Funktion mit angeh\\u00e4ngtem Wert - unauthentifizierte Remote Code Execution. Der legitime Wert ist i\",\"desc_en\":\"Balbooa Forms (com_baforms) up to and incl. 2.4.2.1 - CVE-2026-65880 (CVSS 10.0), actively exploited, fixed only in 2.4.3. Submitting a form with a SIGNATURE field (task=form.sendMessage) makes FormModel::saveSignature use the attacker-supplied function name from the field JSON dynamically as the called function with an appended value - unauthenticated remote code execution. The legitimate value i\",\"default\":1,\"qs\":\"(?=.*\\\\bmethod[^a-z0-9]{1,6}(?:system|exec|shell_exec|passthru|assert|popen|proc_open|pcntl_exec|file_get_contents|readfile|show_source|highlight_file|fopen|scandir|phpinfo|eval|create_function|call_user_func)\\\\b)(?=.*\\\\bimage\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":1,\"trigger\":\"com_baforms\"},{\"id\":\"fabrik-calc-rce\",\"label\":\"Fabrik: unauth. RCE (calc-Element ajax_calc, CVE-2026-66915)\",\"label_en\":\"Fabrik: unauth RCE (calc element ajax_calc, CVE-2026-66915)\",\"desc\":\"Fabrik (com_fabrik) 1.0.0 bis 4.6.6 - CVE-2026-66915 (CVSS 10.0), unauthentifizierte Remote Code Execution. Der oeffentliche AJAX-Endpunkt des calc-Elements (option=com_fabrik, plugin=calc, method=ajax_calc) baut die admin-hinterlegte Rechenformel per parseMessageForPlaceHolder mit ROHEN Request-Werten ($_REQUEST) zusammen und fuehrt sie ueber die @eval-Funktion aus - ein Angreifer schleust ueber \",\"desc_en\":\"Fabrik (com_fabrik) 1.0.0 to 4.6.6 - CVE-2026-66915 (CVSS 10.0), unauthenticated remote code execution. The public AJAX endpoint of the calc element (option=com_fabrik, plugin=calc, method=ajax_calc) assembles the admin-stored calculation formula via parseMessageForPlaceHolder using RAW request values ($_REQUEST) and runs it through the @eval function - an attacker injects PHP code into the formul\",\"default\":1,\"qs\":\"(?=.*option=com_fabrik)(?=.*plugin=calc)(?=.*(?:system|exec|shell_exec|passthru|assert|popen|proc_open|pcntl_exec|file_get_contents|readfile|show_source|highlight_file|fopen|scandir|phpinfo|eval|create_function|call_user_func)\\\\s{0,3}\\\\(\\\\s{0,3}[\\\\x27\\\\x22\\\\x60$])\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":1,\"trigger\":\"com_fabrik\"},{\"id\":\"baforms-eval-rce\",\"label\":\"Balbooa Forms: unauth. RCE (eval via Query-Parameter, CVE-2026-67364)\",\"label_en\":\"Balbooa Forms: unauth RCE (eval via query parameter, CVE-2026-67364)\",\"desc\":\"Balbooa Forms (com_baforms) bis inkl. 2.4.3.1 - CVE-2026-67364 (CVSS 10.0), unauthentifizierte Remote Code Execution. Ein Formular mit eigenem PHP-Nachbearbeitungs-Handler und dem Shortcode [URL parameter=X] setzt den ROHEN, ungefilterten Query-Parameter X in den per eval-Funktion ausgefuehrten PHP-Code ein - ein Angreifer schleust darueber beliebigen PHP-Code ein (der CSRF-Token schuetzt kaum, da\",\"desc_en\":\"Balbooa Forms (com_baforms) up to and incl. 2.4.3.1 - CVE-2026-67364 (CVSS 10.0), unauthenticated remote code execution. A form with a custom PHP post-processing handler and the [URL parameter=X] shortcode substitutes the RAW, unfiltered query parameter X into the PHP code run via the eval function - an attacker injects arbitrary PHP through it (the CSRF token barely protects, being anonymously re\",\"default\":1,\"qs\":\"(?=.*option=com_baforms)(?=.*(?:system|exec|shell_exec|passthru|assert|popen|proc_open|pcntl_exec|file_get_contents|readfile|show_source|highlight_file|fopen|scandir|phpinfo|eval|create_function|call_user_func)\\\\s{0,3}\\\\(\\\\s{0,3}[\\\\x27\\\\x22\\\\x60$])\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":1,\"trigger\":\"com_baforms\"},{\"id\":\"jbusinessdirectory-upload-remove\",\"label\":\"J-Business Directory: unauth. Datei-L\\u00f6schung (upload.remove, CVE-2026-75949)\",\"label_en\":\"J-Business Directory: unauth file deletion (upload.remove, CVE-2026-75949)\",\"desc\":\"J-Business Directory (com_jbusinessdirectory) bis inkl. 6.2.2 - CVE-2026-75949 (CVSS 9.1). Der ohne Login erreichbare Task upload.remove nimmt den _filename-Parameter RAW und erzwingt keine Pfad-Eingrenzung -> ein Angreifer loescht ueber ..\\/-Sequenzen (mit _path_type=2) beliebige Dateien, u. a. configuration.php. SURGICAL: greift NUR, wenn _filename ein Traversal-\\/Nullbyte-Muster enthaelt -> norma\",\"desc_en\":\"J-Business Directory (com_jbusinessdirectory) up to and incl. 6.2.2 - CVE-2026-75949 (CVSS 9.1). The login-free task upload.remove takes the _filename parameter RAW and does not enforce path containment -> an attacker deletes arbitrary files via ..\\/ sequences (with _path_type=2), including configuration.php. SURGICAL: fires ONLY when _filename contains a traversal\\/null-byte pattern -> normal file \",\"default\":1,\"qs\":\"(?=(?:^|.*&)option=com_jbusinessdirectory)(?=.*task=upload(\\\\.|%2e)remove)(?=.*_filename[^&]*(?:\\\\.\\\\.|%2e%2e|%252e|%00))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"all\",\"waf_only\":0,\"trigger\":\"com_jbusinessdirectory\"},{\"id\":\"cottoncloud-cotton\",\"label\":\"Cotton Cloud: unauth. Dateizugriff (com_cotton)\",\"label_en\":\"Cotton Cloud: unauth file access (com_cotton)\",\"desc\":\"CVE-2026-67283 (Cotton Cloud < 2.0.3, CVSS 6.9): die Frontend-Tasks des Datei-Managers com_cotton waren nur per CSRF-Token gesch\\u00fctzt (das Joomla auch nicht eingeloggten Besuchern ausstellt) - ein anonymer Angreifer konnte Dateien lesen, l\\u00f6schen, \\u00fcberschreiben und Rechte \\u00e4ndern. Cotton Cloud gibt jedem Nutzer ein PRIVATES, kontobasiertes Cloud-Laufwerk - es gibt keinen legitimen Gast-Zugriff, d\",\"desc_en\":\"CVE-2026-67283 (Cotton Cloud < 2.0.3, CVSS 6.9): the front-end tasks of the com_cotton file manager were protected by a CSRF token only (which Joomla also issues to visitors who never logged in) - an anonymous attacker could read, delete, overwrite and re-permission files. Cotton Cloud gives every user a PRIVATE, account-based cloud drive - there is no legitimate guest access, so this signature bl\",\"default\":1,\"qs\":\"(?=(?:^|.*&)option=com_cotton\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_cotton\"},{\"id\":\"cottoncloud-shuttle\",\"label\":\"Cotton Cloud: unauth. Terminal-Zugriff (com_shuttle)\",\"label_en\":\"Cotton Cloud: unauth terminal access (com_shuttle)\",\"desc\":\"CVE-2026-67283 (Cotton Cloud < 2.0.3): beide Einstiegspunkte der Terminal-Komponente com_shuttle waren nur per CSRF-Token gesch\\u00fctzt und damit anonym erreichbar. Ein Terminal ist nie gastseitig - diese Signatur blockt jeden GAST-Aufruf von option=com_shuttle im Frontend (kein Payload-Matching, FP-frei; eingeloggte Nutzer nicht betroffen, option an eine echte Query-Grenze gebunden). Fix: Cotton Clo\",\"desc_en\":\"CVE-2026-67283 (Cotton Cloud < 2.0.3): both entry points of the com_shuttle terminal component were protected by a CSRF token only and thus reachable anonymously. A terminal is never guest-facing - this signature blocks every GUEST call of option=com_shuttle on the front end (no payload matching, FP-free; logged-in users not affected, option bound to a real query boundary). Fix: Cotton Cloud 2.0.3\",\"default\":1,\"qs\":\"(?=(?:^|.*&)option=com_shuttle\\\\b)\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"com_shuttle\"},{\"id\":\"sourcerer-reflected-php\",\"label\":\"Sourcerer (Regular Labs): unauth. RCE (reflektierter {source}-PHP-Code)\",\"label_en\":\"Sourcerer (Regular Labs): unauth RCE (reflected {source} PHP code)\",\"desc\":\"CVE-2026-74253 (CVSS 10.0, Sourcerer 1.0.0-15.0.0): Sourcerer ist ein System-Plugin, das gerenderte Inhalte nach seinem Tag {source} durchsucht und darin enthaltenen Code ausf\\u00fchrt. Bis einschlie\\u00dflich 15.0.0 fehlte eine zuverl\\u00e4ssige Herkunftspr\\u00fcfung - reflektierter oder unbest\\u00e4tigter {source}-PHP-Code (z. B. aus einem in die Seite gespiegelten Request-Parameter) wurde serverseitig ausgef\\u00fchrt:\",\"desc_en\":\"CVE-2026-74253 (CVSS 10.0, Sourcerer 1.0.0-15.0.0): Sourcerer is a system plugin that scans rendered output for its {source} tag and executes the code inside. Up to and including 15.0.0 it lacked a reliable origin check - reflected or unverified {source} PHP code (e.g. from a request parameter reflected into the page) was executed on the server: unauthenticated RCE. As there is no component anchor\",\"default\":1,\"qs\":\"(?=.*(?:\\\\x7bsource|%7[bB]source))(?=.*(?:<\\\\?(?:php|=)|%3[cC](?:%3[fF]|\\\\?)(?:php|=)))\",\"uri\":null,\"frontend_only\":1,\"scope\":\"guest\",\"waf_only\":1,\"trigger\":\"source\"},{\"id\":\"traversal-encoded\",\"label\":\"Pfad-Klettern (kodierte Varianten)\",\"label_en\":\"Path traversal (encoded variants)\",\"desc\":\"Erg\\u00e4nzt den Standard-Filter um Umgehungstricks: ....\\/\\/ , doppelte Kodierung (%252e), %c0%ae, %2e%2e%5c.\",\"desc_en\":\"Extends the standard filter with bypass tricks: ....\\/\\/ , double encoding (%252e), %c0%ae, %2e%2e%5c.\",\"default\":1,\"qs\":\"(\\\\.{3,}\\/|%252e|%c0%a[ef]|%2e%2e%5c|\\\\.\\\\.%5c)\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"php-wrapper-uri\",\"label\":\"PHP-Stream-Wrapper im Pfad\",\"label_en\":\"PHP stream wrapper in the path\",\"desc\":\"Blockiert php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ , expect:\\/\\/ u. a. direkt im angefragten Pfad.\",\"desc_en\":\"Blocks php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ , expect:\\/\\/ etc. directly in the requested path.\",\"default\":1,\"qs\":null,\"uri\":\"(?:php|phar|data|expect|glob|zlib|zip):\\/\",\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"api-config-leak\",\"label\":\"Joomla-API Konfigurations-Leak\",\"label_en\":\"Joomla API configuration leak\",\"desc\":\"CVE-2023-23752: sch\\u00fctzt den Endpunkt \\/api\\/...\\/v1\\/config\\/application auch ohne komplette API-Sperre.\",\"desc_en\":\"CVE-2023-23752: protects the \\/api\\/...\\/v1\\/config\\/application endpoint even without a complete API block.\",\"default\":1,\"qs\":null,\"uri\":\"^api\\/index\\\\.php\\/v[0-9]+\\/config\",\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"php-object-injection\",\"label\":\"PHP Object Injection (serialisierte Payload)\",\"label_en\":\"PHP object injection (serialised payload)\",\"desc\":\"Serialisiertes PHP-Objekt in einem Parameter (O:\\/C:<L\\u00e4nge>:) - typischer Einstieg f\\u00fcr Object-Injection\\/POP-Ketten. Kommt in normalen Anfragen nicht vor.\",\"desc_en\":\"Serialised PHP object in a parameter (O:\\/C:<length>:) - typical entry point for object injection\\/POP chains. Does not occur in normal requests.\",\"default\":1,\"qs\":\"(?<![a-z0-9])[oc]:[0-9]{1,4}:\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"stream-wrapper-param\",\"label\":\"PHP-Stream-Wrapper in Parameter\",\"label_en\":\"PHP stream wrapper in a parameter\",\"desc\":\"php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ u. a. als Parameterwert - LFI\\/RCE-Vektor. Erg\\u00e4nzt die Pfad-Variante (php-wrapper-uri).\",\"desc_en\":\"php:\\/\\/ , phar:\\/\\/ , data:\\/\\/ etc. as a parameter value - LFI\\/RCE vector. Complements the path variant (php-wrapper-uri).\",\"default\":1,\"qs\":\"(php|phar|data|expect|glob|zlib|zip):\\/{2}\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null},{\"id\":\"param-traversal\",\"label\":\"Pfad-Klettern im Parameter\",\"label_en\":\"Path traversal in a parameter\",\"desc\":\"Mehrfaches ..\\/ als Parameterwert - generisches Directory-Traversal\\/LFI in beliebigen Komponenten.\",\"desc_en\":\"Repeated ..\\/ as a parameter value - generic directory traversal\\/LFI in any component.\",\"default\":1,\"qs\":\"=(\\\\.\\\\.\\/){2,}\",\"uri\":null,\"frontend_only\":0,\"scope\":\"all\",\"waf_only\":0,\"trigger\":null}],\"vuln_extensions\":[{\"element\":\"aimycaptchalessformguard\",\"type\":\"plugin\",\"folder\":\"captcha\",\"name\":\"Aimy Captcha-Less Form Guard\",\"below\":\"20.1\",\"above\":\"17.0\",\"severity\":\"high\",\"note\":\"Sicherheitsl\\u00fccke in 18.0 bis 20.0, vom Hersteller in 20.1 behoben (freie und PRO-Edition betroffen). Kein Workaround - auf Aimy Captcha-Less Form Guard 20.1 oder neuer aktualisieren.\",\"note_en\":\"Security issue in 18.0 to 20.0, fixed by the vendor in 20.1 (free and PRO edition affected). No workaround - update to Aimy Captcha-Less Form Guard 20.1 or newer.\",\"advisory\":\"https:\\/\\/www.aimy-extensions.com\\/joomla\\/captcha-less-form-guard.html\",\"advisory_en\":\"https:\\/\\/www.aimy-extensions.com\\/joomla\\/captcha-less-form-guard.html\"},{\"element\":\"com_easystore\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EasyStore (JoomShaper)\",\"below\":\"2.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere unauthentifizierte SQL-Injections (CVE-2026-65759 ff.). Auf EasyStore 2.0.2 oder neuer aktualisieren.\",\"note_en\":\"Multiple unauthenticated SQL injections (CVE-2026-65759 ff.). Update to EasyStore 2.0.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65759\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65759\"},{\"element\":\"com_fabrik\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Fabrik\",\"below\":\"4.7.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische unauth. L\\u00fccken bis 4.7.1: RCE \\u00fcber calc-, PHP-Form- und Bild-Element (CVE-2026-66915\\/76604\\/76605, CVSS 10.0), dazu SQLi, Path-Traversal und ACL-Bypass. HTProtect blockt nur die calc-RCE per WAF - auf Fabrik 4.7.2 aktualisieren (schlie\\u00dft alle L\\u00fccken).\",\"note_en\":\"Multiple critical unauth. flaws up to 4.7.1: RCE via calc, PHP form and image elements (CVE-2026-66915\\/76604\\/76605, CVSS 10.0), plus SQL injection, path traversal and ACL bypass. HTProtect blocks only the calc RCE via WAF - update to Fabrik 4.7.2 (fixes all).\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-66915\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-66915\"},{\"element\":\"com_cotton\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Cotton Cloud\",\"below\":\"2.0.3\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-67283 + CVE-2026-67284 (CVSS 6.9): anonyme Besucher konnten Dateien lesen und l\\u00f6schen. HTProtect sperrt den Zugriff bereits per WAF. Auf Cotton Cloud 2.0.3 aktualisieren (2.0.2 reicht nicht).\",\"note_en\":\"CVE-2026-67283 + CVE-2026-67284 (CVSS 6.9): anonymous visitors could read and delete files. HTProtect already blocks the access via the WAF. Update to Cotton Cloud 2.0.3 (2.0.2 is not enough).\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-67283\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-67283\"},{\"element\":\"com_phocacart\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Cart\",\"below\":\"5.2.4\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-74251 (CVSS 9.3): unauthentifizierte SQL-Injection \\u00fcber den Produktfilter (a\\/s). HTProtect blockt g\\u00e4ngige Angriffe per WAF; voller Schutz erst mit Update auf Phoca Cart 5.2.4 bzw. 6.1.7.\",\"note_en\":\"CVE-2026-74251 (CVSS 9.3): unauthenticated SQL injection via the product filter (a\\/s). HTProtect blocks common attacks via the WAF; full protection only after updating Phoca Cart to 5.2.4 or 6.1.7.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-74251\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-74251\"},{\"element\":\"com_phocacart\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Cart\",\"below\":\"6.1.8\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"CVE-2026-74251 (CVSS 9.3): unauthentifizierte SQL-Injection \\u00fcber den Produktfilter (a\\/s) - HTProtect blockt g\\u00e4ngige Angriffe per WAF. Zus\\u00e4tzlich Stored-\\/Reflected-XSS (bis 6.1.7). Voller Schutz erst mit Update auf Phoca Cart 6.1.8 oder neuer.\",\"note_en\":\"CVE-2026-74251 (CVSS 9.3): unauthenticated SQL injection via the product filter (a\\/s) - HTProtect blocks common attacks via the WAF. Additionally stored\\/reflected XSS (up to 6.1.7). Full protection only after updating Phoca Cart to 6.1.8 or newer.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-74251\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-74251\"},{\"element\":\"com_splms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP LMS (JoomShaper)\",\"below\":\"4.1.4\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-48909: unauth. Code-Ausf\\u00fchrung durch unsichere Cookie-Deserialisierung. Auf SP LMS 4.1.4 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48909: unauthenticated code execution via insecure cookie deserialization. Update to SP LMS 4.1.4 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-48909\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-48909\"},{\"element\":\"com_osmembership\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Membership Pro (JoomDonation)\",\"below\":\"4.6.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-62415: kritische L\\u00fccke durch unsichere Standardkonfiguration. Auf Membership Pro 4.6.2 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-62415: critical flaw caused by an insecure default configuration. Update to Membership Pro 4.6.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-62415\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-62415\"},{\"element\":\"com_convertforms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Convert Forms (Tassos)\",\"below\":\"5.2.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische L\\u00fccken bis 5.2.2 (Datei-L\\u00f6schung, Datenleck; CVE-2024-40744); bis 5.2.4 zudem eine fehlende Zugriffskontrolle - Nicht-Angemeldete konnten Formular-Eintr\\u00e4ge auslesen (CVE-2026-77026). Update auf Convert Forms 5.2.5.\",\"note_en\":\"Multiple critical flaws up to 5.2.2 (arbitrary file deletion, data exposure; CVE-2024-40744); up to 5.2.4 also a broken access control - unauthenticated visitors could list a form\'s submissions (CVE-2026-77026). Update to Convert Forms 5.2.5.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-77026\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-77026\"},{\"element\":\"com_jem\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JEM - Joomla Event Manager\",\"below\":\"5.0.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere L\\u00fccken bis 5.0.0: privilegierte Remote-Code-Ausf\\u00fchrung (CVE-2026-77991), anonymes \\u00dcberschreiben\\/Ver\\u00f6ffentlichen von Joomla-Artikeln (CVE-2026-77034), fremde Events\\/Venues \\u00fcbernehmbar (CVE-2026-77035), Teilnehmerlisten f\\u00fcr jeden Eingeloggten lesbar (CVE-2026-77990). Fix in JEM 5.0.1.\",\"note_en\":\"Multiple flaws up to 5.0.0: privileged remote code execution (CVE-2026-77991), anonymous overwrite\\/publish of Joomla articles (CVE-2026-77034), other users\' events\\/venues hijackable (CVE-2026-77035), attendee lists readable by any logged-in user (CVE-2026-77990). Fixed in JEM 5.0.1.\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/jem-joomla-event-manager-disclosure\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/jem-joomla-event-manager-disclosure\\/\"},{\"element\":\"com_joomgallery\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JoomGallery\",\"below\":\"4.4.0\",\"above\":\"4.0.0\",\"severity\":\"medium\",\"note\":\"Zwei L\\u00fccken bis 4.3.x: CVE-2026-66916 (CVSS 6.9, unauth.) - passwortgesch\\u00fctzte Kategorien lie\\u00dfen sich \\u00fcber die JSON-Ansicht am Passwort vorbei auslesen; CVE-2026-66917 - Bearbeiter konnten fremde Inhalte \\u00fcbernehmen und JavaScript einschleusen. Update auf JoomGallery 4.4.0.\",\"note_en\":\"Two flaws up to 4.3.x: CVE-2026-66916 (CVSS 6.9, unauth.) - password-protected categories readable via the JSON view, bypassing the password; CVE-2026-66917 - editors could take over others\' content and inject JavaScript. Update to JoomGallery 4.4.0.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-66916\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-66916\"},{\"element\":\"com_j2store\",\"type\":\"component\",\"folder\":\"\",\"name\":\"J2Store \\/ J2Commerce\",\"below\":\"4.1.6\",\"above\":\"4.1.0\",\"severity\":\"high\",\"note\":\"Zwei unauth. L\\u00fccken bis 4.1.5: \\u00fcber order_id konnten Fremde ganze Bestellungen (Positionen, Preise, Summen) einsehen (CVE-2026-67359, CVSS 8.7), dazu Stored XSS \\u00fcber Gast-Checkout-Felder (CVE-2026-74252). Auf J2Store 4.1.6 aktualisieren.\",\"note_en\":\"Two unauth. flaws up to 4.1.5: via order_id anyone could read entire orders (line items, prices, totals) (CVE-2026-67359, CVSS 8.7), plus stored XSS via guest checkout fields (CVE-2026-74252). Update to J2Store 4.1.6.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-67359\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-67359\"},{\"element\":\"com_j2store\",\"type\":\"component\",\"folder\":\"\",\"name\":\"J2Store \\/ J2Commerce\",\"below\":\"4.0.21\",\"above\":\"4.0.0\",\"severity\":\"high\",\"note\":\"Zwei unauth. L\\u00fccken bis 4.0.20: \\u00fcber order_id konnten Fremde ganze Bestellungen (Positionen, Preise, Summen) einsehen (CVE-2026-67359, CVSS 8.7), dazu Stored XSS \\u00fcber Gast-Checkout-Felder (CVE-2026-74252). Auf J2Store 4.0.21 aktualisieren.\",\"note_en\":\"Two unauth. flaws up to 4.0.20: via order_id anyone could read entire orders (line items, prices, totals) (CVE-2026-67359, CVSS 8.7), plus stored XSS via guest checkout fields (CVE-2026-74252). Update to J2Store 4.0.21.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-67359\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-67359\"},{\"element\":\"com_j2store\",\"type\":\"component\",\"folder\":\"\",\"name\":\"J2Store \\/ J2Commerce\",\"below\":\"3.3.21\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Zwei unauth. L\\u00fccken bis 3.3.20 (Joomla-3-Linie): \\u00fcber order_id konnten Fremde ganze Bestellungen (Positionen, Preise, Summen) einsehen (CVE-2026-67359), dazu Stored XSS \\u00fcber Gast-Checkout-Felder (CVE-2026-74252). Auf J2Store 3.3.21 bzw. 4.1.6 aktualisieren.\",\"note_en\":\"Two unauth. flaws up to 3.3.20 (Joomla 3 line): via order_id anyone could read entire orders (line items, prices, totals) (CVE-2026-67359), plus stored XSS via guest checkout fields (CVE-2026-74252). Update to J2Store 3.3.21 or 4.1.6.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-67359\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-67359\"},{\"element\":\"miniorangeoauth\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"miniOrange OAuth Client\",\"below\":\"3.2.0\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-77995 (kritisch): Auth-Umgehung - gef\\u00e4lschte Cookies gen\\u00fcgten, um sich ohne Anmeldung als beliebiger Nutzer (auch Super-User) einzuloggen. Nur das Update hilft (Cookie-basiert, nicht per Firewall). Update auf miniOrange OAuth Client 3.2.0.\",\"note_en\":\"CVE-2026-77995 (critical): authentication bypass - forged cookies were enough to log in as any user (incl. Super User) without signing in. Only the update helps (cookie-based, no firewall rule). Update to miniOrange OAuth Client 3.2.0.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-77995\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-77995\"},{\"element\":\"com_miniorange_saml\",\"type\":\"component\",\"folder\":\"\",\"name\":\"miniOrange SAML SP (SSO\\/ADFS\\/Google)\",\"below\":\"11.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-77998 (kritisch, CVSS 10.0): Auth-Umgehung \\u00fcber SAMLResponse - lose Signaturpr\\u00fcfung akzeptierte ung\\u00fcltige Signaturen, Login als beliebiger Nutzer (auch Admin). Nur das Update hilft (keine Firewall). Update auf SAML SSO 11.0.2 (ADFS-\\/Google-Edition: 6.4).\",\"note_en\":\"CVE-2026-77998 (critical, CVSS 10.0): auth bypass via SAMLResponse - a loose signature check accepted invalid signatures, login as any user (incl. admin). Only the update helps (no firewall). Update to SAML SSO 11.0.2 (ADFS\\/Google edition: 6.4).\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-77998\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-77998\"},{\"element\":\"sourcerer\",\"type\":\"plugin\",\"folder\":\"editors-xtd\",\"name\":\"Sourcerer (Regular Labs)\",\"below\":\"16.0.0\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-74253 (CVSS 10.0): unauthentifizierte Remote Code Execution - reflektierter oder unbest\\u00e4tigter Sourcerer-Code (alle Versionen bis 15.0.0) wurde serverseitig ausgef\\u00fchrt. HTProtect blockt g\\u00e4ngige Angriffe per WAF; voller Schutz erst mit Update auf Sourcerer 16.0.0.\",\"note_en\":\"CVE-2026-74253 (CVSS 10.0): unauthenticated remote code execution - reflected or unverified Sourcerer code (all versions up to 15.0.0) was executed on the server. HTProtect blocks common attacks via the WAF; full protection only after updating to Sourcerer 16.0.0.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-74253\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-74253\"},{\"element\":\"com_zoo\",\"type\":\"component\",\"folder\":\"\",\"name\":\"ZOO (YOOtheme)\",\"below\":\"4.1.66\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Unauth. Datei-Upload (RCE), SQL-Injection und Stored XSS (CVE-2026-76612) - bis 4.1.65. HTProtect blockt hochgeladene ausf\\u00fchrbare Dateien (Web-Shells); voller Schutz mit Update auf ZOO 4.1.66.\",\"note_en\":\"Unauth. file upload (RCE), SQL injection and stored XSS (CVE-2026-76612) - up to 4.1.65. HTProtect blocks uploaded executable files (web shells); full protection with the update to ZOO 4.1.66.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-76612\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-76612\"},{\"element\":\"yootheme\",\"type\":\"template\",\"folder\":\"\",\"name\":\"YOOtheme Pro\",\"below\":\"5.0.41\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-76613 (CVSS 9.2): SQL-Injection - schon ein Redakteur\\/Autor schleust Inhalt in SQL-Abfragen ein (bis 5.0.40); dazu CVE-2026-75115 (Datei-Lesen, nur Admin). Update auf YOOtheme Pro 5.0.41.\",\"note_en\":\"CVE-2026-76613 (CVSS 9.2): SQL injection - even a contributor injects content into SQL queries (up to 5.0.40); plus CVE-2026-75115 (file read, admin only). Update to YOOtheme Pro 5.0.41.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-76613\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-76613\"},{\"element\":\"com_jbusinessdirectory\",\"type\":\"component\",\"folder\":\"\",\"name\":\"J-Business Directory (CMS Junkie)\",\"below\":\"6.2.3\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische unauth. L\\u00fccken bis 6.2.2: Arbitrary File Upload\\/L\\u00f6schung per Path-Traversal (CVE-2026-75949), Ownership-\\u00dcbernahme (75950), IDOR (75951) und fehlende CSRF-Token (75952). HTProtect blockt die Datei-L\\u00f6schung per WAF; voller Schutz erst mit Update auf J-Business Directory 6.2.3.\",\"note_en\":\"Multiple critical unauthenticated flaws up to 6.2.2: arbitrary file upload\\/deletion via path traversal (CVE-2026-75949), ownership takeover (75950), IDOR (75951) and missing CSRF tokens (75952). HTProtect blocks the file deletion via the WAF; full protection only after updating J-Business Directory to 6.2.3.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-75949\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-75949\"},{\"element\":\"com_easydiscuss\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EasyDiscuss (StackIdeas)\",\"below\":\"5.0.16\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2026-21625: ACL-Umgehung im JSON-Output (Zugriff auf gesch\\u00fctzte Forendaten). Auf EasyDiscuss 5.0.16 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21625: access-control bypass in the JSON output exposing protected forum data. Update to EasyDiscuss 5.0.16 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-21625\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-21625\"},{\"element\":\"com_komento\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Komento (StackIdeas)\",\"below\":\"4.0.8\",\"above\":\"\",\"severity\":\"high\",\"note\":\"CVE-2025-54294: SQL-Injection, ausnutzbar durch unprivilegierte Nutzer. Auf Komento 4.0.8 oder neuer aktualisieren.\",\"note_en\":\"CVE-2025-54294: SQL injection exploitable by unprivileged users. Update to Komento 4.0.8 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-54294\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2025-54294\"},{\"element\":\"nrframework\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Novarain \\/ Tassos Framework\",\"below\":\"6.0.38\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-21627: unauthentifizierte PHP-Einbindung via com_ajax. Auf 6.0.38 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21627: unauthenticated PHP inclusion via com_ajax. Update to 6.0.38 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/joomla-tassos-framework-novarain-framework-sicherheitsluecke\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/joomla-tassos-framework-novarain-framework-sicherheitsluecke\"},{\"element\":\"astroid\",\"type\":\"library\",\"folder\":\"\",\"name\":\"Astroid Framework\",\"below\":\"3.3.11\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-21628: unauthentifizierter Datei-Upload via AJAX-Endpunkt (Dropper in \\/images\\/). Auf 3.3.13 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-21628: unauthenticated file upload via AJAX endpoint (dropper in \\/images\\/). Update to 3.3.13 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/joomla-astroid-framework-sicherheitsluecke-vulnerability\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/joomla-astroid-framework-sicherheitsluecke-vulnerability\"},{\"element\":\"helix3\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Helix3 (JoomShaper)\",\"below\":\"3.1.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-49049: unauthentifizierter com_ajax-Handler (onAjaxHelix3) ohne Login-\\/Rechtepr\\u00fcfung - Angreifer k\\u00f6nnen beliebige Dateien schreiben\\/l\\u00f6schen und Template-Parameter \\u00e4ndern (betroffen bis einschlie\\u00dflich 3.1.1). Auf Helix3 3.1.2 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-49049: unauthenticated com_ajax handler (onAjaxHelix3) with no login or permission check - attackers can write\\/delete arbitrary files and change template parameters (affected up to and including 3.1.1). Update to Helix3 3.1.2 or newer.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-49049\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-49049\"},{\"element\":\"shaper_helix3\",\"type\":\"template\",\"folder\":\"\",\"name\":\"Helix3 Template (shaper_helix3)\",\"below\":\"3.1.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-49049: das Helix3-Template ist \\u00fcber den unauthentifizierten com_ajax-Handler angreifbar - beliebige Dateien schreiben\\/l\\u00f6schen, Template-Parameter \\u00e4ndern (betroffen bis einschlie\\u00dflich 3.1.1). Das Template getrennt vom Plugin auf 3.1.2 aktualisieren.\",\"note_en\":\"CVE-2026-49049: the Helix3 template is reachable through the unauthenticated com_ajax handler - write\\/delete arbitrary files, change template parameters (affected up to and including 3.1.1). Update the template (separately from the plugin) to 3.1.2.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-49049\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-49049\"},{\"element\":\"helixultimate\",\"type\":\"plugin\",\"folder\":\"system\",\"name\":\"Helix Ultimate (JoomShaper)\",\"below\":\"2.2.10\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Kritische unauth. L\\u00fccken bis 2.2.9: com_ajax-Dispatcher ohne Rechtepr\\u00fcfung (Stored XSS, Datei-L\\u00f6schung; Fix 2.2.7) plus 12 weitere Fixes in 2.2.10 (Live-Preview-Bypass via ?helixMode=edit, Media-Upload, Mega-Men\\u00fc-XSS, Titel-Escaping). HTProtect blockt Kern-Angriffe per WAF. Joomla 4\\/5\\/6: auf 2.2.10 aktualisieren; Joomla 3 (Support eingestellt): JoomShapers J3-Security-Patch einspielen.\",\"note_en\":\"Critical unauth flaws up to 2.2.9: com_ajax dispatcher without permission checks (stored XSS, file deletion; fixed 2.2.7) plus 12 more fixes in 2.2.10 (Live Preview bypass via ?helixMode=edit, media upload, Mega Menu XSS, title escaping). HTProtect blocks core attacks via the WAF. Joomla 4\\/5\\/6: update to 2.2.10; Joomla 3 (support ended): install JoomShaper\'s J3 security patch.\",\"advisory\":\"https:\\/\\/htprotect.org\\/helix-ultimate\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/helix-ultimate\"},{\"element\":\"shaper_helixultimate\",\"type\":\"template\",\"folder\":\"\",\"name\":\"Helix Ultimate Template (shaper_helixultimate)\",\"below\":\"2.2.10\",\"above\":\"2.2.7\",\"severity\":\"critical\",\"note\":\"Das Helix-Ultimate-TEMPLATE (getrennt vom Plugin; aktualisiert sich nicht \\u00fcber den Joomla-Updater) ist von 2.2.7 bis 2.2.9 verwundbar: Media-Upload-Bypass, Path-Traversal, Broken Access Control und Stored XSS. Das Template separat auf 2.2.10 aktualisieren.\",\"note_en\":\"The Helix Ultimate TEMPLATE (separate from the plugin; does not update via the Joomla updater) is vulnerable from 2.2.7 to 2.2.9: media upload bypass, path traversal, broken access control and stored XSS. Update the template separately to 2.2.10.\",\"advisory\":\"https:\\/\\/htprotect.org\\/helix-ultimate\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/helix-ultimate\"},{\"element\":\"com_baforms\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Balbooa Forms\",\"below\":\"2.4.3.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische unauth. RCE-L\\u00fccken bis 2.4.3.1 (eval-Injection CVE-2026-67364, Signatur-Feld CVE-2026-65880, Datei-Upload). HTProtect blockt Web-Shell-Uploads und die eval-\\/Signatur-RCE per WAF; voller Schutz erst mit Update auf Balbooa Forms 2.4.3.2 oder neuer.\",\"note_en\":\"Multiple critical unauthenticated RCE flaws up to 2.4.3.1 (eval injection CVE-2026-67364, signature field CVE-2026-65880, file upload). HTProtect blocks web-shell uploads and the eval\\/signature RCE via the WAF; full protection only after updating Balbooa Forms to 2.4.3.2 or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-67364\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-67364\"},{\"element\":\"com_jce\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JCE Editor\",\"below\":\"2.9.99.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-48907: unauthentifizierter Webshell-Upload (profiles.import + plugin.rpc). Dringend auf JCE 2.9.99.6 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-48907: unauthenticated webshell upload (profiles.import + plugin.rpc). Urgently update to JCE 2.9.99.6 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/jce-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/jce-sicherheitsluecke-joomla\"},{\"element\":\"com_rsfiles\",\"type\":\"component\",\"folder\":\"\",\"name\":\"RSFiles!\",\"below\":\"1.17.12\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Aktiver unauth. Datei-Upload -> RCE bis 1.17.11: anonymer Upload ohne Login-\\/Endungspr\\u00fcfung, .php ausf\\u00fchrbar. HTProtects Gast-Upload-Schutz blockt den Upload bereits. Auf RSFiles 1.17.12 aktualisieren.\",\"note_en\":\"Active unauthenticated file upload -> RCE up to 1.17.11: anonymous upload with no login\\/extension check, .php executable. The HTProtect guest-upload filter already blocks the upload. Update to RSFiles 1.17.12.\",\"advisory\":\"https:\\/\\/www.rsjoomla.com\\/blog\\/view\\/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html\",\"advisory_en\":\"https:\\/\\/www.rsjoomla.com\\/blog\\/view\\/644-unauthenticated-file-upload-fixed-in-rsfiles-version-11712-update-now.html\"},{\"element\":\"com_edocman\",\"type\":\"component\",\"folder\":\"\",\"name\":\"EDocman\",\"below\":\"3.9\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Unauthentifizierte SQL-Injection bis 3.8: ein anonymer Besucher schleust \\u00fcber einen Filter-Parameter im Frontend SQL ein und liest die Datenbank aus (bis hin zu Zugangsdaten). Auf EDocman 3.9.0 aktualisieren.\",\"note_en\":\"Unauthenticated SQL injection up to 3.8: an anonymous visitor injects SQL via a front-end filter parameter and can read the database (up to credentials). Update to EDocman 3.9.0.\",\"advisory\":\"https:\\/\\/joomdonation.com\\/forum\\/edocman\\/82813-edocman-3-9-0-security-release---important-update-recommended.html\",\"advisory_en\":\"https:\\/\\/joomdonation.com\\/forum\\/edocman\\/82813-edocman-3-9-0-security-release---important-update-recommended.html\"},{\"element\":\"com_foranalytics\",\"type\":\"component\",\"folder\":\"\",\"name\":\"4Analytics\",\"below\":\"5.0.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-57833 und CVE-2026-58077: zwei unauthentifizierte, kritische Sicherheitsl\\u00fccken (ohne Login angreifbar) in allen Versionen vor 5.0.2. Dringend auf 4Analytics 5.0.2 aktualisieren.\",\"note_en\":\"CVE-2026-57833 and CVE-2026-58077: two unauthenticated, critical security flaws (exploitable without login) in all versions before 5.0.2. Update to 4Analytics 5.0.2 urgently.\",\"advisory\":\"https:\\/\\/weeblr.com\\/blog\\/critical-vulnerabilities-2026-07-15\",\"advisory_en\":\"https:\\/\\/weeblr.com\\/blog\\/critical-vulnerabilities-2026-07-15\"},{\"element\":\"com_quix\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Quix\",\"below\":\"6.2.1\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Unauthentifizierte SQL-Injection (CVSS 8.7, alle Versionen vor 6.2.1): ein anonymer Besucher kann die gesamte Datenbank auslesen. HTProtects Mini-WAF blockt den Angriff bereits. Auf Quix 6.2.1 aktualisieren.\",\"note_en\":\"Unauthenticated SQL injection (CVSS 8.7, all versions below 6.2.1): an anonymous visitor can read the entire database. HTProtect\'s mini-WAF already blocks the attack. Update to Quix 6.2.1.\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/quix-sql-injection-disclosure\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/quix-sql-injection-disclosure\\/\"},{\"element\":\"com_joomcck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"JoomCCK\",\"below\":\"6.4.1\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"CVE-2026-49048: unauthentifizierte SQL-Injection \\u00fcber die Tag-Funktion - ein anonymer Besucher kann die Datenbank auslesen und ver\\u00e4ndern. HTProtects Mini-WAF blockt bereits. Auf JoomCCK 6.4.1 aktualisieren.\",\"note_en\":\"CVE-2026-49048: unauthenticated SQL injection via the tag function - an anonymous visitor can read and modify the database. HTProtect\'s mini-WAF already blocks it. Update to JoomCCK 6.4.1.\",\"advisory\":\"https:\\/\\/github.com\\/JoomCoder-com\\/JoomCCK\\/releases#release-6.4.1\",\"advisory_en\":\"https:\\/\\/github.com\\/JoomCoder-com\\/JoomCCK\\/releases#release-6.4.1\"},{\"element\":\"com_chronoforms8\",\"type\":\"component\",\"folder\":\"\",\"name\":\"ChronoForms\",\"below\":\"8.0.53\",\"above\":\"8.0.0\",\"severity\":\"high\",\"note\":\"CVE-2026-58148 (CVSS 8.7): unauthentifizierte gespeicherte XSS - anonym eingeschleustes JavaScript wird sp\\u00e4ter im Backend ausgef\\u00fchrt und kann die Admin-Sitzung \\u00fcbernehmen. Auf ChronoForms 8.0.53 aktualisieren.\",\"note_en\":\"CVE-2026-58148 (CVSS 8.7): unauthenticated stored XSS - JavaScript injected anonymously runs later in the backend and can take over the admin session. Update to ChronoForms 8.0.53.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-58148\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-58148\"},{\"element\":\"com_jdownloads\",\"type\":\"component\",\"folder\":\"\",\"name\":\"jDownloads\",\"below\":\"4.1.6\",\"above\":\"4.1.0\",\"severity\":\"high\",\"note\":\"Unauthentifizierter Datei-Upload (Versionen 4.1.0-4.1.5): anonym sind beliebige Dateien hochladbar, teils bis zur Codeausf\\u00fchrung. HTProtect blockt den Zugriff bereits (403). Auf jDownloads 4.1.6 aktualisieren.\",\"note_en\":\"Unauthenticated file upload (versions 4.1.0-4.1.5): anonymous visitors can upload arbitrary files, up to code execution on some servers. HTProtect already blocks direct access (403). Update to jDownloads 4.1.6.\",\"advisory\":\"https:\\/\\/www.jdownloads.com\\/index.php\\/news\\/jdownloads-4-1-6-secure-update-released.html\",\"advisory_en\":\"https:\\/\\/www.jdownloads.com\\/index.php\\/news\\/jdownloads-4-1-6-secure-update-released.html\"},{\"element\":\"com_dpcalendar\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DPCalendar\",\"below\":\"10.12.0\",\"above\":\"9.0.0\",\"severity\":\"high\",\"note\":\"DPCalendar (Joomla 4.4-6, vor 10.12.0): unauthentifizierte SQL-Injection \\u00fcber den Autor-Filter (anonym, nur lesend - HTProtects Mini-WAF blockt sie bereits) plus authentifizierte Blind-SQL-Injection \\u00fcber gespeicherte Artikel und Stored XSS in Standort-Titeln (erfordern Redakteur-\\/Standort-Rechte, nicht WAF-abfangbar). Voller Schutz erst mit Update auf 10.12.0; die 9.x-Reihe hat keinen Patch.\",\"note_en\":\"DPCalendar (Joomla 4.4-6, below 10.12.0): unauthenticated SQL injection via the author filter (anonymous, read-only - HTProtect\'s mini-WAF already blocks it) plus authenticated blind SQL injection via saved articles and stored XSS in location titles (require author\\/location privileges, not WAF-blockable). Full protection only after updating to 10.12.0; the 9.x line has no patch.\",\"advisory\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\",\"advisory_en\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\"},{\"element\":\"com_dpcalendar\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DPCalendar\",\"below\":\"8.19.5\",\"above\":\"8.18.0\",\"severity\":\"high\",\"note\":\"DPCalendar f\\u00fcr Joomla 3 (8.18.0-8.19.4): unauthentifizierte Blind-SQL-Injection \\u00fcber den Autor-Filter (nur lesend - HTProtect blockt sie per WAF) plus authentifizierte SQL-Injection \\u00fcber gespeicherte Artikel und Stored XSS in Standort-Titeln (erfordern Redakteur-\\/Standort-Rechte). Voller Schutz mit Update auf DPCalendar 8.19.5.\",\"note_en\":\"DPCalendar for Joomla 3 (8.18.0-8.19.4): unauthenticated blind SQL injection via the author filter (read-only - HTProtect blocks it via the WAF) plus authenticated SQL injection via saved articles and stored XSS in location titles (require author\\/location privileges). Full protection with the update to DPCalendar 8.19.5.\",\"advisory\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\",\"advisory_en\":\"https:\\/\\/joomla.digital-peak.com\\/blog\\/2026-security-issue-in-dpcalendar\"},{\"element\":\"com_phocadownload\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Download\",\"below\":\"6.1.5\",\"above\":\"6.0.0\",\"severity\":\"high\",\"note\":\"Authentifizierter Datei-Upload -> RCE (6.0-6.1.2; HTProtects PHP-Schild verhindert die Ausf\\u00fchrung) sowie Reflected XSS \\u00fcber den Such-Parameter (bis 6.1.4). Auf Phoca Download 6.1.5 oder neuer aktualisieren.\",\"note_en\":\"Authenticated file upload -> RCE (6.0-6.1.2; HTProtect\'s PHP shield prevents execution) plus reflected XSS via the search parameter (up to 6.1.4). Update to Phoca Download 6.1.5 or newer.\",\"advisory\":\"https:\\/\\/www.phoca.cz\\/news\\/1508-phoca-download-version-6-1-5-released-security-release\",\"advisory_en\":\"https:\\/\\/www.phoca.cz\\/news\\/1508-phoca-download-version-6-1-5-released-security-release\"},{\"element\":\"com_phocamaps\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Maps\",\"below\":\"6.1.0\",\"above\":\"5.0.0\",\"severity\":\"medium\",\"note\":\"CVE-2026-65763: reflektiertes XSS (5.0.0-6.0.4) durch unzureichende Eingabepr\\u00fcfung - ein pr\\u00e4parierter Link f\\u00fchrt beim Besucher eingeschleustes JavaScript aus. Auf Phoca Maps 6.1.0 aktualisieren.\",\"note_en\":\"CVE-2026-65763: reflected XSS (5.0.0-6.0.4) via improper input validation - a crafted link runs injected JavaScript in a visitor\'s browser. Update to Phoca Maps 6.1.0.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65763\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65763\"},{\"element\":\"com_phocaguestbook\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Phoca Guestbook\",\"below\":\"6.1.1\",\"above\":\"5.0.0\",\"severity\":\"medium\",\"note\":\"CVE-2026-65762: reflektiertes XSS (5.0.0-6.1.0) durch unzureichende Eingabepr\\u00fcfung - ein pr\\u00e4parierter Link f\\u00fchrt beim Besucher eingeschleustes JavaScript aus. Auf Phoca Guestbook 6.1.1 (Security-Release) oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-65762: reflected XSS (5.0.0-6.1.0) via improper input validation - a crafted link runs injected JavaScript in the visitor\'s browser. Update to Phoca Guestbook 6.1.1 (security release) or newer.\",\"advisory\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65762\",\"advisory_en\":\"https:\\/\\/nvd.nist.gov\\/vuln\\/detail\\/CVE-2026-65762\"},{\"element\":\"com_acym\",\"type\":\"component\",\"folder\":\"\",\"name\":\"AcyMailing 6+\",\"below\":\"10.11.1\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-56292: unauthentifizierte SQL-Injection in AcyMailing 6+ (6.0.0-10.11.0), anonym die Datenbank inkl. Passwort-Hashes auslesbar. Weitere: CVE-2023-28731 (Upload\\/RCE), CVE-2026-3614 (Rechteausweitung). Auf AcyMailing 10.11.1 aktualisieren.\",\"note_en\":\"CVE-2026-56292: unauthenticated SQL injection in AcyMailing 6+ (6.0.0-10.11.0), anonymous read of the database incl. password hashes. Also: CVE-2023-28731 (upload\\/RCE), CVE-2026-3614 (privilege escalation). Update to AcyMailing 10.11.1.\",\"advisory\":\"https:\\/\\/htprotect.org\\/acymailing\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/acymailing\"},{\"element\":\"com_acymailing\",\"type\":\"component\",\"folder\":\"\",\"name\":\"AcyMailing Classic\",\"below\":\"4.9.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"AcyMailing Classic (End-of-Life): anonymer Datei-Upload\\/RCE der 3.x-\\u00c4ra und Backend-SQL-Injection CVE-2015-7338 (in 4.9.5 behoben); CVE-2018-9107 (CSV-Injection) ist niedrig. Auf eine unterst\\u00fctzte AcyMailing-Version migrieren.\",\"note_en\":\"AcyMailing Classic (end-of-life): anonymous file upload\\/RCE of the 3.x era and backend SQL injection CVE-2015-7338 (fixed in 4.9.5); CVE-2018-9107 (CSV injection) is low. Migrate to a supported AcyMailing version.\",\"advisory\":\"https:\\/\\/htprotect.org\\/acymailing\",\"advisory_en\":\"https:\\/\\/htprotect.org\\/en\\/acymailing\"},{\"element\":\"com_igallery\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Ignite Gallery\",\"below\":\"5.4.1\",\"above\":\"5.0.0\",\"severity\":\"high\",\"note\":\"Ignite Gallery 5.0.0-5.4.0: Stored XSS (hoch) durch fehlendes Escaping bei Bild-Uploads, dazu SSRF und Rechteausweitung. Nur ausnutzbar mit Upload-\\/Bearbeitungsrecht. Auf Ignite Gallery 5.4.1 aktualisieren.\",\"note_en\":\"Ignite Gallery 5.0.0-5.4.0: stored XSS (high) via missing output escaping on image uploads, plus SSRF and privilege escalation. Only exploitable with upload\\/edit permission. Update to Ignite Gallery 5.4.1.\",\"advisory\":\"https:\\/\\/www.ignitegallery.com\\/documentation\\/changelog\",\"advisory_en\":\"https:\\/\\/www.ignitegallery.com\\/documentation\\/changelog\"},{\"element\":\"com_icagenda\",\"type\":\"component\",\"folder\":\"\",\"name\":\"iCagenda\",\"below\":\"4.0.12\",\"above\":\"4.0.0\",\"severity\":\"critical\",\"note\":\"CVE-2026-67365 (CVSS 9.2): unauthentifizierte SQL-Injection im Kalender-Modul, Datenbank ohne Login auslesbar. 4.0.12 behebt zudem CVE-2026-67366 und CVE-2026-48939. HTProtect blockt g\\u00e4ngige SQLi per WAF; voller Schutz mit Update auf iCagenda 4.0.12.\",\"note_en\":\"CVE-2026-67365 (CVSS 9.2): unauthenticated SQL injection in the calendar module, database readable without login. 4.0.12 also fixes CVE-2026-67366 and CVE-2026-48939. HTProtect blocks common SQLi via the WAF; full protection with the update to iCagenda 4.0.12.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-67365\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-67365\"},{\"element\":\"com_icagenda\",\"type\":\"component\",\"folder\":\"\",\"name\":\"iCagenda\",\"below\":\"3.9.15\",\"above\":\"3.2.1\",\"severity\":\"critical\",\"note\":\"CVE-2026-48939 (3.x-Linie f\\u00fcr Joomla 3): anonymer Datei-Upload im Event-Formular ohne Rechtepr\\u00fcfung. HTProtects Dateischild verhindert die Ausf\\u00fchrung bereits; voller Schutz erst mit Update auf iCagenda 3.9.15.\",\"note_en\":\"CVE-2026-48939 (3.x line for Joomla 3): anonymous file upload in the event form without a permission check. The HTProtect file shield already prevents execution; full protection only after updating iCagenda to 3.9.15.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/icagenda-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/icagenda-sicherheitsluecke-joomla\"},{\"element\":\"com_sppagebuilder\",\"type\":\"component\",\"folder\":\"\",\"name\":\"SP Page Builder\",\"below\":\"6.8.0\",\"above\":\"6.0.0\",\"severity\":\"critical\",\"note\":\"CVE-2026-65876 (CVSS 8.7): unauth. SQL-Injection \\u00fcber den \\u201eMehr laden\\\"-Artikel-Endpunkt. Auf SP Page Builder 6.8.0 oder neuer aktualisieren.\",\"note_en\":\"CVE-2026-65876 (CVSS 8.7): unauth. SQL injection via the article load-more endpoint. Update to SP Page Builder 6.8.0 or newer.\",\"advisory\":\"https:\\/\\/website-bereinigung.de\\/blog\\/sp-page-builder-sicherheitsluecke-joomla\",\"advisory_en\":\"https:\\/\\/website-bereinigung.de\\/en\\/blog\\/sp-page-builder-sicherheitsluecke-joomla\"},{\"element\":\"com_pagebuilderck\",\"type\":\"component\",\"folder\":\"\",\"name\":\"PageBuilder CK\",\"below\":\"3.6.5\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"Mehrere kritische L\\u00fccken bis 3.6.4: anonymer Datei-Upload mit Codeausf\\u00fchrung (CVE-2026-56290\\/63048, die Fixes bis 3.6.2 waren unvollst\\u00e4ndig) und SQL-Injection (CVE-2026-74254). HTProtect blockt Upload und Ausf\\u00fchrung bereits; voller Schutz erst mit Update auf PageBuilder CK 3.6.5.\",\"note_en\":\"Several critical flaws up to 3.6.4: anonymous file upload with code execution (CVE-2026-56290\\/63048, fixes up to 3.6.2 were incomplete) and SQL injection (CVE-2026-74254). HTProtect already blocks the upload and execution; full protection only after updating PageBuilder CK to 3.6.5.\",\"advisory\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-63048\",\"advisory_en\":\"https:\\/\\/www.cve.org\\/CVERecord?id=CVE-2026-63048\"},{\"element\":\"com_eventbooking\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Events Booking\",\"below\":\"5.8.1\",\"above\":\"5.0\",\"severity\":\"medium\",\"note\":\"Zwei unauthentifizierte L\\u00fccken vor 5.8.1: anonymer Datei-Upload und eine Schnittstelle, die zu jeder Benutzernummer Name und E-Mail preisgibt (ganze Nutzerliste auslesbar). Auf Events Booking 5.8.1 aktualisieren; 5.8.0 gen\\u00fcgt nicht.\",\"note_en\":\"Two unauthenticated flaws before 5.8.1: anonymous file upload and an interface that returns the name and e-mail for any user number (entire user list readable). Update to Events Booking 5.8.1; 5.8.0 is not enough.\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/events-booking-unauthenticated-upload-user-enumeration\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/events-booking-unauthenticated-upload-user-enumeration\\/\"},{\"element\":\"com_djclassifieds\",\"type\":\"component\",\"folder\":\"\",\"name\":\"DJ-Classifieds\",\"below\":\"3.11.2\",\"above\":\"\",\"severity\":\"high\",\"note\":\"Aktiv ausgenutzte L\\u00fccke bis 3.11.1: anonymer Upload von Anzeigenbildern ohne Login und ohne Pr\\u00fcfung - ein Angreifer legt eine Schaddatei ab und \\u00fcbernimmt die Seite. Auf DJ-Classifieds 3.11.2 aktualisieren.\",\"note_en\":\"Actively exploited flaw up to 3.11.1: anonymous upload of ad images with no login and no checks - an attacker plants a malicious file and takes over the site. Update to DJ-Classifieds 3.11.2.\",\"advisory\":\"https:\\/\\/mysites.guru\\/blog\\/dj-classifieds-unauthenticated-file-upload\\/\",\"advisory_en\":\"https:\\/\\/mysites.guru\\/blog\\/dj-classifieds-unauthenticated-file-upload\\/\"},{\"element\":\"com_gridbox\",\"type\":\"component\",\"folder\":\"\",\"name\":\"Gridbox\",\"below\":\"2.20.2\",\"above\":\"\",\"severity\":\"critical\",\"note\":\"CVE-2026-61425 und weitere kritische L\\u00fccken bis 2.20.1: unbefugter Datei-Zugriff, Ordner-L\\u00f6schung, SQL-Injektionen und umgehbare Rechtepr\\u00fcfung. 2.20.1 reicht nicht - auf Balbooa Gridbox 2.20.2 aktualisieren.\",\"note_en\":\"CVE-2026-61425 and further critical flaws up to 2.20.1: unauthorized file access, folder deletion, SQL injections and authorization bypasses. 2.20.1 is not enough - update to Balbooa Gridbox 2.20.2.\",\"advisory\":\"https:\\/\\/www.balbooa.com\\/blog\\/gridbox\\/gridbox-2-20-2-security-release\",\"advisory_en\":\"https:\\/\\/www.balbooa.com\\/blog\\/gridbox\\/gridbox-2-20-2-security-release\"}],\"php_min\":\"8.1\",\"fetched\":\"2026-08-27 23:38:33\",\"fetched_ts\":1787929992,\"etag\":\"\\\"6a90b88d-1454e\\\"\",\"modified\":\"Thu, 27 Aug 2026 22:22:05 GMT\",\"joomla_latest\":{\"3\":\"3.10.12\",\"4\":\"4.4.14\",\"5\":\"5.4.8\",\"6\":\"6.1.3\"},\"joomla_latest_ts\":1787936572,\"joomla_latest_try\":1787936572},\"htp_malware\":{\"schema\":1,\"version\":\"2026-08-16.041727\",\"sigs\":[{\"id\":\"backdoor-prepend-sshkey\",\"all\":[\"auto_prepend_file\",\"authorized_keys\"]},{\"id\":\"cred-stealer-ctfaudit\",\"any\":[\"x-ctf-audit\",\"jlib_audit_gid\"]},{\"id\":\"upload-shell-form\",\"all\":[\"move_uploaded_file\",\"check directory permissions\"]},{\"id\":\"sppb-iconfont-shell\",\"any\":[\"sppbwhoami\"]},{\"id\":\"remote-eval-loader\",\"all\":[\"eval(\\\"?>\\\"\"],\"any\":[\"fetchcontentfromurl\",\"file_get_contents(\\\"http\",\"file_get_contents(\'http\"]},{\"id\":\"seo-doorway-slot\",\"any\":[\"slot gacor\",\"situs slot gacor\"]},{\"id\":\"filemanager-backdoor-data\",\"all\":[\"<?php exit;?>{\",\"\\\"groupinfo\\\"\",\"\\\"sizemax\\\"\"]},{\"id\":\"encrypted-eval-openssl\",\"all\":[\"openssl_raw_data\",\"aes-256-cbc\"],\"not\":[\"openssl_decrypt\",\"openssl_encrypt\"]},{\"id\":\"0xnix-split-encrypted\",\"all\":[\"0xnix encrypted code\"]},{\"id\":\"upload-shell-devco1\",\"all\":[\"move_uploaded_file\",\"devco1\"]},{\"id\":\"upload-shell-uname-form\",\"all\":[\"move_uploaded_file\",\"php_uname\",\"multipart\\/form-data\"]},{\"id\":\"hacktool-adminer\",\"all\":[\"adminer_errors\",\"idf_unescape\"]},{\"id\":\"webshell-range-obfuscator\",\"all\":[\"\\\"r\\\".\\\"a\\\".\\\"n\\\".\\\"g\\\".\\\"e\\\"\",\"eval\"]},{\"id\":\"webshell-md5quad-gate\",\"all\":[\"md5(md5(md5(md5(\",\"eval\"]},{\"id\":\"remote-loader-stream-include\",\"any\":[\"include stream_get_meta_data\",\"require stream_get_meta_data\",\"include(stream_get_meta_data\",\"require(stream_get_meta_data\"]},{\"id\":\"webshell-dual-uploader\",\"all\":[\"remote_url\",\"name=\\\"_upl\\\"\",\"name=\\\"_remote\\\"\"]},{\"id\":\"webshell-comment-obfuscator\",\"all\":[\"-*\\/\\/\\/\",\"\\\"~\\\"\"]},{\"id\":\"eval-openssl-shell\",\"label\":\"eval(openssl_decrypt) webshell\",\"all\":[\"eval(openssl_decrypt(\"]},{\"id\":\"dropper-drivergenius-c2\",\"label\":\"Remote-fetch dropper (drivergenius C2)\",\"all\":[\"drivergenius.it.com\"]},{\"id\":\"dropper-backdate-disguise\",\"label\":\"Remote-fetch dropper (mtime-forge + disguise)\",\"all\":[\"getreferencefiletime\",\"generatefilename\"]},{\"id\":\"js-inject-fake-cleaned\",\"label\":\"JS injection w\\/ fake \\\"cleaned\\/safe\\\" comment\",\"all\":[\"artifacts of previous malicious infection\",\"dangerous code has been removed\"]},{\"id\":\"linkforge-seo-injector\",\"label\":\"LinkForge SEO backlink injector\",\"all\":[\"linkforge.cc\"]},{\"id\":\"seo-doorway-cloak\",\"label\":\"SEO cloaking doorway (Thai gambling, fake sitemap)\",\"all\":[\"output_sitemap_page\",\"is_from_google\",\"send_404_and_exit\"]},{\"id\":\"helix-ultimate-xss\",\"label\":\"Helix Ultimate mega-menu XSS campaign\",\"any\":[\"xss.report\",\"_hu_inject\",\"_huinject\",\"sessionstorage._hxd\"]},{\"id\":\"gsocket-c2\",\"label\":\"gsocket reverse-shell C2 marker\",\"any\":[\"gs_args\"]},{\"id\":\"cloak-engine-thiscitze\",\"label\":\"thiscitze SEO cloaking engine\",\"all\":[\"thiscitze\"]},{\"id\":\"cloak-doorway-jsurl-jumpurl\",\"label\":\"Thai gambling SEO cloaking\\/doorway injector\",\"all\":[\"$js_url\",\"$jump_url\"]},{\"id\":\"cn-aes-loader\",\"label\":\"AES-decrypt + gzinflate eval loader\",\"all\":[\"openssl_decrypt\",\"gzinflate\",\"eval(\\\"?>\\\"\"]},{\"id\":\"cn-loader-tag\",\"label\":\"Chinese \'PHP code security loader\' tag\",\"all\":[\"php\\u4ee3\\u7801\\u5b89\\u5168\\u52a0\\u8f7d\\u5668\"]},{\"id\":\"menu-api-filemanager\",\"label\":\"MENU_API file-manager webshell\",\"all\":[\"menu_api_password\"]},{\"id\":\"remote-eval-curl\",\"label\":\"curl remote-fetch eval loader\",\"all\":[\"eval(\\\"?>\\\"\",\"curl_exec\"]},{\"id\":\"bujang-c2\",\"label\":\"Remote-fetch loader (bujang.online C2)\",\"all\":[\"bujang.online\"]},{\"id\":\"tinyfilemanager-tool\",\"label\":\"Tiny File Manager (webshell-capable file manager)\",\"all\":[\"tinyfilemanager\"]},{\"id\":\"webshell-split-strrev-system\",\"all\":[\"\\\"st\\\".\\\"rr\\\".\\\"ev\\\"\",\"\\\"s\\\".\\\"ys\\\".\\\"tem\\\"\"]},{\"id\":\"webshell-split-b64-fgc\",\"all\":[\"\\\"base6\\\".\\\"4_d\\\".\\\"ecode\\\"\",\"\\\"fil\\\".\\\"e_get_cont\\\".\\\"ents\\\"\"]}],\"names\":[{\"id\":\"probe-d1337\",\"m\":[\"_d1337_\"],\"label\":\"d1337 write-access probe \\/ dropper marker\"},{\"id\":\"probe-write-test\",\"m\":[\"_probe_\"],\"label\":\"generic write-access probe marker (_probe_)\"}],\"scan_ext\":[],\"ack\":[\"6608daed700e0afc330788b2a272ca8d\",\"67b5f9a00c7aabf34261c715aeeaadba\",\"9812b693256a0c306cc53368559c7a4b\",\"ec96a3bed6681af996fd37f0818cba6b\",\"abfe3b7513994ae6ac2f33129b5f6e7b\",\"fb2e76c5ebafc2b8ea82e0d35d45fa02\",\"2ec54ce00420cd41dfae5abedc9edcb7\",\"02c1a767857c55d31cae7277bc43bac2\",\"573a5e7374be2925911b552d485a28f3\",\"cdf24443c39d943f8750d4a4420e6581\",\"99af93b919c5b6bc14a82382c39010ec\",\"55e704bb88a8f9ab0d756976c527516b\",\"981b4f5e07bf9cd1249d60d659e4ef93\",\"87d978102ed075a8e58074a0d3595c30\",\"85648deb8324a11400ecaebcfd04ae16\",\"323707d28051b4cbf161420f5f1bb499\",\"19104a261abbdffe7cd1713949b286cf\",\"a72013015988ad7d978ce9841a9668dd\",\"a8af9b93d27c774601e1d8a902145bd7\",\"82c8de717e67a620ca503a1a01a7d909\",\"a8192a3cf6279862054cb3092dad82bf\",\"eae8beb708347cfe54bf87506b572f41\",\"5db6f4cdd20dfee86e05110a2276d748\",\"872e97edc1d4247d2ed86d35f468ff88\",\"da9c67c9b7be2d5a7eb9113d76119abc\",\"d0c5a881e845f93a72e1450259de0d33\",\"ea531694f501221b61a324d3754da603\",\"b8333a512d949684c91c9dd907f9cb0c\",\"2c57aea21d161fe5761ffab0abff8228\",\"93117860cd06939707a4ff1797bebb40\",\"7f58961ebcc0db81b16c2d16072fb084\",\"760423f79cedc17e78df95505e93f0c7\",\"d8b0c0f2faf44495f7954fe826720bad\",\"b9b6b8553113e745ebef3251b5d223b9\",\"3e5d03ecb5de8ab2ff1790d7b78bee24\",\"0cd3f898084fe66b062ab5162d2b370c\",\"deb26b6603b6edd8381f6c77fc53cace\",\"0855cf0d6a33b86a8506aeeb769e4343\",\"bcfa5def6057812cba39996c13c1feb3\",\"b719915e7d46c753fe4aeb7a6b8e7fea\",\"913459ac4f3b49356595a341f9b2ac03\",\"e902a6e687aa6cc1398cce5a55fb9905\",\"619cb219bc0492b46608717514204eeb\",\"3ac0ed83859d47acc729c20767afb925\"],\"community\":0,\"fp\":[{\"all\":[\"easycalccheckplus\"],\"only\":[\"rce\"],\"id\":\"ecc-plus-doc-rce\"},{\"all\":[\"phpoffice\\\\phpspreadsheet\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"phpspreadsheet-lib\"},{\"any\":[\"cp_errordocument\",\"status-reason\"],\"not\":[\"<!--#exec\",\"<?\"],\"only\":[\"shtml\"],\"id\":\"plesk-error-shtml\"},{\"all\":[\"gumlet\",\"data:\\/\\/application\\/octet-stream\"],\"only\":[\"wrapper\"],\"id\":\"gumlet-imageresize-datawrapper\"},{\"all\":[\"data:\\/\\/image\",\"exif_read_data\"],\"only\":[\"wrapper\"],\"id\":\"exif-data-wrapper\"},{\"all\":[\"phpoffice\\\\phpword\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"phpword-lib\"},{\"all\":[\"box\\\\spout\"],\"only\":[\"mixedcase\",\"wrapper\"],\"id\":\"box-spout-lib\"},{\"all\":[\"sarciszewski\\\\phpfuture\"],\"only\":[\"wrapper\"],\"id\":\"php-future-lib\"},{\"all\":[\"baformsmodelform\"],\"only\":[\"feed:upload-shell-uname-form\"],\"id\":\"fp-baforms-model\"},{\"all\":[\"quixnxt\"],\"only\":[\"goto\"],\"id\":\"fp-quix-goto\"},{\"all\":[\"varexporter\"],\"only\":[\"goto\"],\"id\":\"fp-symfony-varexporter-goto\"},{\"all\":[\"valorapps.com\"],\"only\":[\"idxbuild\"],\"id\":\"fp-easyfolderlisting-changelog\"},{\"all\":[\"matomo.org\"],\"only\":[\"rce\"],\"id\":\"fp-matomo-rce\"},{\"all\":[\"namespace tracy\"],\"only\":[\"phtml\"],\"id\":\"fp-tracy-phtml\"},{\"all\":[\"guzzlehttp\",\"requestfsm\"],\"only\":[\"goto\"],\"id\":\"fp-guzzle-requestfsm\"},{\"all\":[\"siteguarding.com\",\"siteguarding_server_ip1\"],\"only\":[\"feed:upload-shell-uname-form\"],\"id\":\"fp-siteguarding-agent\"},{\"all\":[\"muruguard\"],\"only\":[\"feed:helix-ultimate-xss\"],\"id\":\"fp-muruguard-scanner\"},{\"all\":[\"<svg\"],\"not\":[\"<script\",\"<?php\",\"<?=\",\"onload=\",\"onerror=\",\"onmouseover=\",\"onclick=\",\"onfocus=\",\"javascript:\",\"<foreignobject\"],\"only\":[\"tmp_exec\"],\"id\":\"fp-benign-svg-tmp\"}],\"seo\":{\"weights\":[],\"keywords\":[],\"sigs\":[]},\"recall\":[],\"fetched\":\"2026-08-27 18:59:07\",\"fetched_ts\":1787924002,\"etag\":\"\\\"6a90754e-21f4\\\"\",\"modified\":\"Thu, 27 Aug 2026 17:35:10 GMT\"},\"htp_incidents\":[]}'
WHERE `type` = 'component' AND `element` = 'com_htprotect'