CVE-2026-66915
Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.6.9 - An unauthenticated attacker could execute arbitrary code by using the ajax_calc feature of the calc plugin.
- Affected products
- Fabrik
- CVSS 4.0
- 10.0 CRITICAL
- EPSS
- 0.6% (46th percentile)
- Weakness
- CWE-94
- NVD status
- Received
- Published
- 2026-08-10
CVE-2026-66915 at NVD
2 known exploits for CVE-2026-66915
Proof-of-concept code and exploit modules indexed by Sploitus