CyberICT

CVE-2026-65883

Aimy Extensions · Published July 29, 2026

CVSS v3.1

CRITICAL

Description

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

Affected Products

  • Aimy Captcha Less Form Guard <= 20.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H