Exploiting critical bugs in Joomla extensions

CISA warns about two critical vulnerabilities in Joomla extensions (iCagenda and Balbooa Forms) that allow remote code execution. Find out how

martes, 14 de julio de 2026 • 5 min read • Q2BSTUDIO Team

Critical vulnerabilities in iCagenda and Balbooa Forms

The recent inclusion of two critical vulnerabilities in Joomla extensions in CISA's catalog of known exploited vulnerabilities (KEVs) has once again brought to the table a recurring problem in web security: third-party components. Joomla, which powers about 1.2% of all websites in the world, relies heavily on extensions developed by independent companies. When these pieces are seriously flawed, the risk extends to thousands of portals, from personal blogs to corporate platforms. The two vulnerabilities detected affect iCagenda, an event calendar, and Balbooa Forms, a popular form builder. Both have received the maximum score of CVSS 10, which indicates an extreme level of danger. Attackers have taken advantage of these flaws to upload malicious files to servers and execute PHP code remotely, taking full control of the compromised site.

The case of iCagenda is particularly alarming because the bug is found in the functionality of attaching files within the 'Send an event' form. Any visitor, without the need for authentication, could send a PHP file disguised as an image or document. In the absence of rigorous file type validation, the server stored it in an accessible directory and then executed it. Researchers at mySites.guru detected automated attacks just hours before patched versions 4.0.8 and 3.9.15 were released in mid-June. The scanners scoured the internet for vulnerable sites to install webshells. Balbooa Forms had a similar vulnerability: its front-end upload point accepted files from anonymous users without any CSRF protection or type checking. This allowed a PHP file to be uploaded to a public directory and executed. The Balbooa company responded with version 2.4.1 on July 9, but exploitation continues on unupdated sites.

These incidents highlight the need for a comprehensive cybersecurity strategy that goes beyond the core of the CMS. Organizations using Joomla should regularly audit installed extensions, apply security patches as soon as they become available, and have intrusion detection mechanisms in place. Additionally, any custom software development that integrates with the site should follow good secure coding practices. In this sense, having a specialized technology partner makes all the difference. Q2BSTUDIO, for example, offers cybersecurity services that include penetration testing and vulnerability analysis, helping to identify and fix these weaknesses before they are exploited. It also develops custom applications with a focus on security by design, minimizing the attack surface.

Beyond Joomla, the ecosystem of extensions of any CMS (WordPress, Drupal, Magento) faces similar challenges. Independent developers don't always have the resources to conduct deep security audits, and site administrators often blindly rely on popular plugins. The lesson here is that security cannot be a late addition; it must be integrated into each layer. For example, when contracting AWS and Azure cloud services to host the web, it is crucial to correctly configure security groups, file permissions, and access logs. Q2BSTUDIO advises on secure cloud architecture, ensuring that even if one extension is vulnerable, the rest of the infrastructure is not compromised.

Another relevant aspect is intelligent monitoring. Today, artificial intelligence for companies makes it possible to deploy AI agents that analyze web traffic in real time and detect anomalous patterns, such as suspicious file uploads or requests to sensitive directories. These systems can automatically block exploitation attempts before they materialize. Combined with business intelligence tools like Power BI, administrators can visualize security metrics and make informed decisions. Q2BSTUDIO integrates these capabilities into its process automation solutions and business intelligence services, providing a proactive defense ecosystem.

The vulnerability in Balbooa Forms, in particular, stands out for its simplicity: an endpoint without authentication or validation. This reminds us that the most common mistakes are usually the most dangerous. Many developers underestimate file uploading, assuming that users will only send legitimate content. But the reality is that attackers automate the search for these weak spots. That's why, when developing custom software, it's critical to whitelist file types, rename uploaded files, and store them outside of the web root. If a 'principle of least privilege' approach is also used, the impact of a potential breach is drastically reduced.

For companies that manage Joomla sites, the immediate action is to update both extensions to their fixed versions. But long-term thinking needs to go further: evaluate the software supply chain and establish a process of continuous review of all components. In a context where cyberattacks are increasingly sophisticated, it is not enough to react; We have to anticipate. Investing in cybersecurity is not an expense, but a protection of the most valuable asset: user trust and brand reputation.

From a business perspective, outsourcing security management to specialists allows organizations to focus on their core business. Q2BSTUDIO offers services ranging from the development of secure applications to the implementation of resilient cloud infrastructures. In addition, their teams are trained in the latest hardening and incident response techniques. If your company uses Joomla or any other CMS, consider conducting a security audit with professionals. Prevention will always be cheaper than remediation after an attack.

In conclusion, the exploitation of these two critical vulnerabilities in Joomla extensions is a reminder that web security is a dynamic process. It's not enough to install a CMS and forget about it; You need to keep it up to date, audit your add-ons, and adopt a defense-in-depth mindset. With the support of firms such as Q2BSTUDIO, companies can navigate this landscape with greater peace of mind, knowing that they have customized software solutions, artificial intelligence applied to security and top-notch cloud services. Technology advances, and with it threats; but also the tools to protect what matters most.

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.