SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-64876

HIGH · CVSS 8.8 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-07-23 · Last synced 2026-08-22

CyberRota Analysis

AI-Generated

The GeoIP extension for Joomla contains inconsistent CSRF token and privilege checks, allowing unauthorized database updates due to insufficient validation mechanisms. This vulnerability poses a high risk, as it can be exploited to manipulate or compromise the integrity of the database. Joomla administrators and users of the GeoIP extension should prioritize addressing this issue to mitigate potential unauthorized access and data integrity risks.

CVE
CVE-2026-64876
Severity
HIGH
CVSS
8.8
EPSS
0.13%

Original NVD Description

Joomla Extension - regularlabs.com - Inconsistent CSRF token checks / privilege checks in GeoIP extension - Database-update requests lacked consistent token and Super User checks, this could cause unauthorized updates.