CVE-2026-65883
Aimy Extensions · Published July 29, 2026
9.8
CVSS v3.1
CRITICALDescription
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
Affected Products
- Aimy Captcha Less Form Guard <= 20.0
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H