Junglewise Threat Intelligence

CVE-2026-65883: Aimy Captcha-Less Form Guard PHP object injection in clfgd field

CVE-2026-65883 · Severity: info · CVSS 10 · Published 2026-07-29

Executive brief

Aimy Captcha-Less Form Guard is a Joomla extension used to protect website forms from automated spam bots without requiring user interaction. A critical security flaw in versions 18.0 through 20.0 allows an attacker to execute malicious code on the web server by sending a specially crafted form submission. This could lead to a complete takeover of the website, theft of customer data, or a total service outage.

Technical details

A PHP Object Injection vulnerability exists in the Aimy Captcha-Less Form Guard plugin (plg_captcha_aimycaptchalessformguard) for Joomla. The root cause is the insecure deserialization of untrusted data provided via a forged 'clfgd' form field. A remote, unauthenticated attacker can exploit this by submitting a crafted request containing a malicious PHP serialized object. If the application contains suitable 'gadget chains,' this leads to Remote Code Execution (RCE) on the underlying server. The vulnerability is present in versions 18.0 through 20.0 and has been addressed in version 20.1.

Affected products

  • aimy-extensions.com Aimy Captcha-Less Form Guard 18.0 - 20.0

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory
  • 2026-07-29: patched: Version 20.1 released

References