JoomlaForever.com!
  • Home
  • About US
  • News
  • Test & Reviews
  • Tutorials
  • Tips & Tricks
  • Contact US
  • Login

News - Security News

JoomlaForever.com! No image is available

Patch Balbooa Forms 2.4.1 for CVE-2026-56291 RCE

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 18 July 2026

Balbooa Forms (com_baforms) versions before 2.4.1 are affected by CVE-2026-56291, an actively exploited unauthenticated file-upload vulnerability that can lead to remote code execution. Joomla administrators should identify exposed installations, update to 2.4.1 or later without delay, and review affected sites for signs of unauthorised uploads or code execution.

Read more: Patch Balbooa Forms 2.4.1 for CVE-2026-56291 RCE

JoomlaForever.com! No image is available

Accept Monero on Joomla with xmr-pay for HikaShop and VirtueMart

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 18 July 2026

xmr-pay packages described for HikaShop and VirtueMart give Joomla shop operators a route to evaluate Monero as a payment option without treating the integration as a security disclosure. This practical guide focuses on planning, staging-site validation, operational controls and a cautious production rollout for stores that decide the payment method suits their business.

Read more: Accept Monero on Joomla with xmr-pay for HikaShop and VirtueMart

JoomlaForever.com! No image is available

Critical Page Builder CK RCE: Patch and Check for Web Shells

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 18 July 2026

CVE-2026-56290 is a critical unauthenticated file-upload vulnerability in Page Builder CK for Joomla that can lead to remote code execution. Because CISA lists the issue as actively exploited, affected site owners should verify their extension version, apply the latest vendor-confirmed fix, and assess exposed sites for signs of compromise.

Read more: Critical Page Builder CK RCE: Patch and Check for Web Shells

JoomlaForever.com! No image is available

What to Do When Your Host Reports a Malicious File on Your Joomla Site

Details
Written by: Bjørn Ove Bremnes
Parent Category: News
Category: News - Security News
Published: 18 July 2026

A malicious-file alert from your hosting provider deserves prompt, methodical action—not a rushed deletion. This general Joomla incident-response guide explains how to verify the report, preserve evidence, clean safely, restore trusted files, and reduce the risk of reinfection.

Read more: What to Do When Your Host Reports a Malicious File on Your Joomla Site

Page 2 of 6

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6

About us

JF Logo

JoomlaForever.com is an independent source publishing news and tests about Joomla CMS.

Contact info

  • JoomlaForever.com!
  • Contact owner:  Bjørn Ove Bremnes
  • General info:
Social Medial:
  • JoomlaForever on Facebook
  • JoomlaForever on Twitter / X

Useful links

  • Home
  • About JoomlaForever.com
  • Disclaimer
  • Privacy Policy
  • Terms and Conditions
  • Comments Policy
  • Sitemap
  • Register account
  • Login
This site is sponsored by:
Bredc.com logo

All our content is original, and therefore it's copyrighted by JoomlaForever.com!

If you wish to use our content on another site, you will need explicit allowance from JoomlaForever.com! You can do this by emailing  or by using our form (see "Useful links")!

ALL RIGHTS © 2019 - 2026.
JoomlaForever.com!, and this site is not affiliated with or endorsed by The Joomla! Project™. Any products and services provided through this site are not supported or warrantied by The Joomla! Project or Open Source Matters, Inc. Use of the Joomla!® name, symbol, logo and related trademarks is permitted under a limited license granted by Open Source Matters, Inc...