Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

File-upload

13 articles tagged File-upload, newest first.

Balbooa Forms 2.4.3.4 Fixes Five Security Issues

Balbooa Forms 2.4.3.4 Fixes Five Security Issues

Balbooa Forms 2.4.3.4 fixes five CVEs in the Joomla form builder, led by a 9.5 unauthenticated RCE. Every version below 2.4.3.4 is affected. Update now.

JoomGallery 4.4.2 Fixes an Unauthenticated File Upload

JoomGallery 4.4.2 Fixes an Unauthenticated File Upload

JoomGallery 4.0.0 to 4.4.1 accept uploads from anyone with no login. Install 4.4.2. The CVE briefly named 4.4.1 as the fix before it was corrected.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66

YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.

PageBuilder CK RCE fixed - again - correctly this time

PageBuilder CK RCE fixed - again - correctly this time

PageBuilder CK's 3.6.0 fix for its file-upload RCE (CVE-2026-56290) added just a login check; any Editor could still run code. Fixed in 3.6.3. Be on 3.6.5.

Membership Pro 4.6.2: A Quiet Fix for Anonymous File Uploads

Membership Pro 4.6.2: A Quiet Fix for Anonymous File Uploads

Membership Pro 4.6.2 fixes the same anonymous upload flaw we reported in Events Booking. Now CVE-2026-62415, rated critical. What to do about it.

DJ-Classifieds Unauthenticated File Upload

DJ-Classifieds Unauthenticated File Upload

DJ-Classifieds below 3.11.2 let anyone upload files to your Joomla site with no login, and it was being used in the wild. Update to 3.11.2 now.

jDownloads 4.1 Shipped an Unauthenticated Upload Endpoint, Now Fixed in 4.1.6

jDownloads 4.1 Shipped an Unauthenticated Upload Endpoint, Now Fixed in 4.1.6

jDownloads 4.1.0 to 4.1.5 shipped a leftover test script that let anyone upload files to your Joomla site with no login. Update to 4.1.6, which removes it.

Phoca Download 6.1.3 Fixes an Authenticated Upload RCE

Phoca Download 6.1.3 Fixes an Authenticated Upload RCE

Phoca Download for Joomla (com_phocadownload) up to 6.1.2 let a logged-in member upload a PHP file and run code on the server. Fixed in 6.1.3, update now.

RSFiles! Fixes an Unauthenticated File Upload RCE

RSFiles! Fixes an Unauthenticated File Upload RCE

RSFiles! for Joomla (com_rsfiles) up to 1.17.11 had an unauthenticated file upload flaw letting anyone drop a PHP file and run code. Update now.

Balbooa Forms Fixes an Unauthenticated File Upload RCE

Balbooa Forms Fixes an Unauthenticated File Upload RCE

CVE-2026-56291: unauthenticated file upload RCE in Balbooa Forms (com_baforms) for Joomla, fixed in 2.4.1. More security releases followed: update to 2.4.3.4.

PageBuilder CK File Upload RCE - June 2026

PageBuilder CK File Upload RCE - June 2026

PageBuilder CK below 3.6.0 lets anyone upload and run a file on your Joomla site, no login. CVE-2026-56290, CVSS 10.0, exploited in the wild. Update to 3.6.0.

Zero Day Vulnerability Found in iCagenda Joomla Extension

Zero Day Vulnerability Found in iCagenda Joomla Extension

mySites.guru found and confirmed an unauthenticated upload giving remote code execution on Joomla 6 sites running iCagenda. Fixed same-day in 4.0.8.

SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins

SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins

An unauthenticated upload in the SP Page Builder Joomla extension gives remote code execution and creates hidden Super User accounts. Fixed in 6.6.2.

Browse every article