File-upload
13 articles tagged File-upload, newest first.

Balbooa Forms 2.4.3.4 Fixes Five Security Issues
Balbooa Forms 2.4.3.4 fixes five CVEs in the Joomla form builder, led by a 9.5 unauthenticated RCE. Every version below 2.4.3.4 is affected. Update now.

JoomGallery 4.4.2 Fixes an Unauthenticated File Upload
JoomGallery 4.0.0 to 4.4.1 accept uploads from anyone with no login. Install 4.4.2. The CVE briefly named 4.4.1 as the fix before it was corrected.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66
YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.

PageBuilder CK RCE fixed - again - correctly this time
PageBuilder CK's 3.6.0 fix for its file-upload RCE (CVE-2026-56290) added just a login check; any Editor could still run code. Fixed in 3.6.3. Be on 3.6.5.

Membership Pro 4.6.2: A Quiet Fix for Anonymous File Uploads
Membership Pro 4.6.2 fixes the same anonymous upload flaw we reported in Events Booking. Now CVE-2026-62415, rated critical. What to do about it.

DJ-Classifieds Unauthenticated File Upload
DJ-Classifieds below 3.11.2 let anyone upload files to your Joomla site with no login, and it was being used in the wild. Update to 3.11.2 now.

jDownloads 4.1 Shipped an Unauthenticated Upload Endpoint, Now Fixed in 4.1.6
jDownloads 4.1.0 to 4.1.5 shipped a leftover test script that let anyone upload files to your Joomla site with no login. Update to 4.1.6, which removes it.

Phoca Download 6.1.3 Fixes an Authenticated Upload RCE
Phoca Download for Joomla (com_phocadownload) up to 6.1.2 let a logged-in member upload a PHP file and run code on the server. Fixed in 6.1.3, update now.

RSFiles! Fixes an Unauthenticated File Upload RCE
RSFiles! for Joomla (com_rsfiles) up to 1.17.11 had an unauthenticated file upload flaw letting anyone drop a PHP file and run code. Update now.

Balbooa Forms Fixes an Unauthenticated File Upload RCE
CVE-2026-56291: unauthenticated file upload RCE in Balbooa Forms (com_baforms) for Joomla, fixed in 2.4.1. More security releases followed: update to 2.4.3.4.

PageBuilder CK File Upload RCE - June 2026
PageBuilder CK below 3.6.0 lets anyone upload and run a file on your Joomla site, no login. CVE-2026-56290, CVSS 10.0, exploited in the wild. Update to 3.6.0.

Zero Day Vulnerability Found in iCagenda Joomla Extension
mySites.guru found and confirmed an unauthenticated upload giving remote code execution on Joomla 6 sites running iCagenda. Fixed same-day in 4.0.8.
SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins
An unauthenticated upload in the SP Page Builder Joomla extension gives remote code execution and creates hidden Super User accounts. Fixed in 6.6.2.