Vulnerability Details CVE-2026-65883
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.005
EPSS Ranking 40.0%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2026-65883
-
cpe:2.3:a:aimy-extensions:aimy_captcha-less_form_guard:18.0
-
cpe:2.3:a:aimy-extensions:aimy_captcha-less_form_guard:18.1
-
cpe:2.3:a:aimy-extensions:aimy_captcha-less_form_guard:19.0
-
cpe:2.3:a:aimy-extensions:aimy_captcha-less_form_guard:19.1
-
cpe:2.3:a:aimy-extensions:aimy_captcha-less_form_guard:19.2
-
cpe:2.3:a:aimy-extensions:aimy_captcha-less_form_guard:20.0