File-upload
11 articles tagged File-upload, newest first.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66
YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.

PageBuilder CK RCE fixed - again - correctly this time
PageBuilder CK's 3.6.0 fix for its file-upload RCE (CVE-2026-56290) added just a login check; any Editor could still run code. Fixed in 3.6.3. Be on 3.6.5.

Membership Pro 4.6.2: A Quiet Fix for Anonymous File Uploads
Membership Pro 4.6.2 quietly fixes the same anonymous upload flaw we reported in Events Booking. Now CVE-2026-62415, rated critical. What to do about it.

DJ-Classifieds Unauthenticated File Upload
DJ-Classifieds below 3.11.2 let anyone upload files to your Joomla site with no login, and it was being used in the wild. Update to 3.11.2 now.

jDownloads 4.1 Shipped an Unauthenticated Upload Endpoint, Now Fixed in 4.1.6
jDownloads 4.1.0 to 4.1.5 shipped a leftover test script that let anyone upload files to your Joomla site with no login. Update to 4.1.6, which removes it.

Phoca Download 6.1.3 Fixes an Authenticated Upload RCE
Phoca Download for Joomla (com_phocadownload) up to 6.1.2 let a logged-in member upload a PHP file and run code on the server. Fixed in 6.1.3, update now.

RSFiles! Fixes an Unauthenticated File Upload RCE
RSFiles! for Joomla (com_rsfiles) up to 1.17.11 had an unauthenticated file upload flaw letting anyone drop a PHP file and run code. Update now.

Balbooa Forms Fixes an Unauthenticated File Upload RCE
Balbooa Forms (com_baforms) had an unauthenticated file upload RCE, CVE-2026-56291, fixed in 2.4.1. Three more security releases followed: update to 2.4.3.2.

PageBuilder CK File Upload RCE - June 2026
PageBuilder CK below 3.6.0 lets anyone upload and run a file on your Joomla site, no login. CVE-2026-56290, CVSS 10.0, exploited in the wild. Update to 3.6.0.

Zero Day Vulnerability Found in iCagenda Joomla Extension
mySites.guru found and confirmed an unauthenticated upload giving remote code execution on Joomla 6 sites running iCagenda. Fixed same-day in 4.0.8.
SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins
An unauthenticated upload in the SP Page Builder Joomla extension gives remote code execution and creates hidden Super User accounts. Fixed in 6.6.2.