Description
Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
Published: 2026-07-29
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A forged clfgd field in the Aimy Captcha-Less Form Guard extension allows an attacker to inject a PHP object that is deserialized by the application, which satisfies CWE-502. The vulnerability provides a direct path to execute arbitrary PHP code on the Joomla site, giving an attacker full control over the server and, depending on the Joomla configuration, the ability to tamper with site data, install backdoors, or further compromise the environment.

Affected Systems

Aim Extensions operates the Aimy Captcha-Less Form Guard plugin for Joomla. Versions 18.0 through 20.0 are affected and expose the deserialization flaw. Joomla sites that have installed any of these versions are susceptible.

Risk and Exploitability

The CVSS score of 10 reflects the high impact of remote code execution. EPSS indicates a low probability of exploitation at present, with the score shown as <1%. The vulnerability is not listed in the CISA KEV catalog. The attack vector is remote, requiring the submission of a crafted HTTP request containing a bogus clfgd field; no additional authentication or privilege escalation steps are described, so the flaw can be used from an unauthenticated client that can access the form. Given the severity, even low exploitation probability warrants rapid action.

Generated by OpenCVE AI on August 3, 2026 at 13:30 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Aimy Captcha-Less Form Guard to any version newer than 20.0 if available from aimy-extensions.com
  • If an upgrade cannot be performed immediately, disable or uninstall the plugin to remove the vulnerable code path
  • Implement input validation or filtering for the clfgd field within your Joomla forms to reject forged submissions

Generated by OpenCVE AI on August 3, 2026 at 13:30 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Aimy-extensions.com
Aimy-extensions.com aimy Captcha-less Form Guard Plugin For Joomla
Vendors & Products Aimy-extensions.com
Aimy-extensions.com aimy Captcha-less Form Guard Plugin For Joomla

Wed, 29 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 10:30:00 +0000

Type Values Removed Values Added
Description Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.
Title Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0
Weaknesses CWE-502
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Aimy-extensions Aimy Captcha-less Form Guard
Aimy-extensions.com Aimy Captcha-less Form Guard Plugin For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-29T14:39:53.741Z

Reserved: 2026-07-23T09:17:01.409Z

Link: CVE-2026-65883

cve-icon Vulnrichment

Updated: 2026-07-29T12:21:52.860Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T11:16:50.297

Modified: 2026-08-05T18:37:29.990

Link: CVE-2026-65883

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T13:30:04Z

Weaknesses
  • CWE-502

    Deserialization of Untrusted Data