CISA flags active RCE exploitation in Joomla extensions; separate SQLi fix lands for Quix Page Builder

Originally published at: CISA flags active RCE exploitation in Joomla extensions; separate SQLi fix lands for Quix Page Builder - ToolsLib Blog

CISA added two actively exploited Joomla extension flaws to its KEV catalog, warning of RCE via file uploads in iCagenda and Balbooa Forms. Separately, Quix Page Builder patched an unauthenticated SQL injection in version 6.2.1.