What is CVE-2026-65883?
CVE-2026-65883 is a Remote Code Execution (RCE) vulnerability in the Aimy Captcha-Less Form Guard Joomla extension, caused by PHP object injection via a forged 'clfgd' field. It affects versions 18.0 through 20.0. Immediately update the extension or disable it temporarily to mitigate the risk.
Azərbaycanca: CVE-2026-65883, Joomla üçün Aimy Captcha-Less Form Guard əlavəsində 'clfgd' sahəsi vasitəsilə PHP object injection zəifliyidir. 18.0-20.0 versiyalarını təsir edir və uzaqdan kod icrasına (RCE) səbəb ola bilər. Dərhal əlavəni yeniləmək və ya müvəqqəti olaraq deaktiv etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-502
FAQ2
Which Joomla extension is affected by CVE-2026-65883?
This vulnerability affects the Aimy Captcha-Less Form Guard extension.
What is the technical cause of the RCE in CVE-2026-65883?
The vulnerability is caused by PHP object injection via a forged 'clfgd' field.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.