SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64875

MEDIUM · CVSS 6.5 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The GeoIP extension for Joomla is vulnerable to IP spoofing due to its reliance on potentially spoofable forwarded client-IP headers, which may allow attackers to bypass GeoIP-based access controls. This could lead to unauthorized access or manipulation of content based on geographic location. Joomla administrators and users of the GeoIP extension should prioritize this vulnerability to mitigate potential security risks.

CVE
CVE-2026-64875
Severity
MEDIUM
CVSS
6.5
EPSS
0.21%

Original NVD Description

Joomla Extension - regularlabs.com - IP spoofing vulnerability in GeoIP extension - GeoIP lookups trusted spoofable forwarded client-IP headers, this could cause GeoIP-rule bypass.