SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65881

HIGH · CVSS 7.5 EPSS 0.24%

Source: NVD + CISA KEV + EPSS · Published 2026-07-28 · Last synced 2026-08-27

CyberRota Analysis

AI-Generated

The Joomdle extension prior to version 3.1.1 has an insecure default configuration that permits unauthorized read and write access to user accounts, including the ability to reset passwords. This vulnerability poses a significant risk to Joomla-based websites, as it can lead to account compromise and unauthorized access to sensitive information. Website administrators using this extension should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-65881
Severity
HIGH
CVSS
7.5
EPSS
0.24%

Original NVD Description

Joomla Extension - joomdle.com - Insecure default configuration allows read/write user account access in Joomdle < 3.1.1 - The default configuration of the extension allowed read access and password reset of CMS accounts.