CVE-2026-65883: Aimy-Extensions Aimy Captcha-Less Form Guard
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
Affected products
- Aimy-Extensions Aimy Captcha-Less Form Guard: from 18.0, up to and including 20.0
Published 2026-07-29. Last modified 2026-08-05.