CVE-2026-76605
published 2026-08-22CVE-2026-76605: Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.
PriorityP262critical10CVSS 4.0
AVNACLATNPRNUINVCHVIHVAHSCHSIHSAHEXCRXIRXARXMAVXMACXMATXMPRXMUIXMVCXMVIXMVAXMSCXMSIXMSAXSXAUXRXVXREXUX
EPSS
0.70%
51.1th percentile
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| fabrikar.com | fabrik_extension_for_joomla | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Fabrikar Fabrik Extension up to 4.7.2 Image Element code injection
vuldb·2026-08-24·CVSS 10.0
CVE-2026-76605 [CRITICAL] Fabrikar Fabrik Extension up to 4.7.2 Image Element code injection
A vulnerability has been found in Fabrikar Fabrik Extension up to 4.7.2 and classified as critical. Impacted is an unknown function of the component Image Element. The manipulation leads to code injection.
This vulnerability is referenced as CVE-2026-76605. Remote exploitation of the attack is possible. No exploit is available.
GHSA
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
ghsa_unreviewed·2026-08-22
CVE-2026-76605 [CRITICAL] CWE-94 Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.3 - ???.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-22
Published