Joomla Extensions iCagenda and Balbooa Forms Hit by Reported Zero-Day Attacks

Joomla Extensions iCagenda and Balbooa Forms Hit by Reported Zero-Day Attacks

Security reports say two widely used Joomla add-ons, iCagenda and Balbooa Forms, have weaknesses that attackers are actively exploiting before official fixes are available.

Joomla is one of the most widely used open-source content management systems (CMS) for building websites. A CMS is software that lets non-technical people create and manage web pages without coding. Joomla can be extended with small programs called extensions or plugins that add features like event calendars or contact forms. Security researchers have reported that two such extensions, iCagenda and Balbooa Forms, contain security weaknesses that are being actively attacked as zero-days. A zero-day is a vulnerability that becomes known to attackers before the software maker has had a chance to publish a fix. This means website owners using these extensions may have no official patch available yet, and their sites could be taken over or used to steal visitor data.

The exact technical details of the flaws in iCagenda and Balbooa Forms have not been fully disclosed, but the reported active exploitation means attackers have found ways to abuse these extensions in the wild. In typical Joomla extension attacks, malicious actors exploit weaknesses like improper input validation (not checking user-supplied data), insecure file uploads, or missing access controls. Such flaws can allow an attacker to add their own code to a website, create hidden administrator accounts, or extract sensitive information from the database. Because extensions are often developed by third parties outside the core Joomla team, their security quality varies, and updates may be slower to arrive.

This situation highlights a broader risk for any website that relies on third-party add-ons. Even when the core platform is kept up to date, a single vulnerable extension can provide an entry point. Joomla sites are particularly attractive targets because they often run on shared hosting environments where many sites reside on the same server. If one site is compromised through a vulnerable extension, the attacker may attempt to move laterally to other sites on the same server. For website owners, this means regular auditing of every extension is essential, not just the core CMS.

For hosting providers and managed service operators, zero-day exploits in popular extensions require rapid detection and response. Security monitoring, web application firewalls (software or hardware that filters incoming web traffic and blocks known attack patterns), and file integrity monitoring can help spot suspicious activity before damage spreads. Backup systems are equally important; a clean, recent backup allows a quick restoration if a site is defaced or corrupted. Since Joomla does not have a central automatic update mechanism for all third-party extensions, the responsibility for patching often falls on the site owner.

Website owners using Joomla should immediately check their installed extensions for iCagenda and Balbooa Forms. If either is present, consider disabling it until the developer releases a confirmed fix. Monitor the official Joomla security announcements and the extension developers' websites for patches. In the meantime, strengthen overall security by changing all administrator passwords, enabling two-factor authentication (a second step beyond a password, like a code from a phone app), and reviewing user accounts for any that look unfamiliar. A web application firewall can also block many exploit attempts even before a patch is available.

For organizations that need help securing their Joomla installations or other web applications, AEU-I provides security-first IT and consulting services that can include vulnerability assessments, patching guidance, and proactive monitoring to reduce the risk of zero-day attacks. While no service can guarantee complete immunity from undisclosed vulnerabilities, having an experienced security partner can dramatically shorten the time between detection and mitigation.

How to Protect Yourself

  1. If you run a Joomla website, log in to your administration area and look for iCagenda or Balbooa Forms in the list of installed extensions; if you find either, turn it off until the developers release a safe update.
  2. Set up automatic update notifications for all Joomla extensions and install any updates as soon as they appear, even if you are busy.
  3. Turn on two-factor authentication for your Joomla administrator account, which requires a short code from your phone in addition to your password.
  4. Make a full backup of your website files and database today, and store it somewhere separate from your hosting account.
  5. Ask your hosting provider or security team to enable a web application firewall, a tool that filters incoming website traffic and blocks many attack attempts before they reach your site.

Related AEU services

  • AEU-I IT and security consulting