The U.S. cybersecurity agency CISA has warned of active exploitation of file-upload flaws in two Joomla extensions: iCagenda and Balbooa Forms.
Improperly validated file-upload flaws can be abused by attackers to upload malicious files and take over a site. Owners of Joomla-based sites using these extensions are advised to update or disable them immediately.
The case highlights the importance of keeping all site components โ including third-party plugins and extensions โ up to date. Website security is a chain only as strong as its weakest link.