Skip to main content
mySites.guru
4+ live

Joomla extension security alerts (26 Aug) Sourcerer 16.0.0Fabrik 4.7.2ZOO: unauth RCEJCE 2.9.99.10

File-upload

11 articles tagged File-upload, newest first.

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66

A CVSS 10.0 Unauthenticated Upload in YOOtheme ZOO, Fixed in 4.1.66

YOOtheme ZOO (com_zoo) up to 4.1.63 had an unauthenticated file upload RCE scored CVSS 10.0, plus a SQL injection, fixed in 4.1.64. Install 4.1.66.

PageBuilder CK RCE fixed - again - correctly this time

PageBuilder CK RCE fixed - again - correctly this time

PageBuilder CK's 3.6.0 fix for its file-upload RCE (CVE-2026-56290) added just a login check; any Editor could still run code. Fixed in 3.6.3. Be on 3.6.5.

Membership Pro 4.6.2: A Quiet Fix for Anonymous File Uploads

Membership Pro 4.6.2: A Quiet Fix for Anonymous File Uploads

Membership Pro 4.6.2 quietly fixes the same anonymous upload flaw we reported in Events Booking. Now CVE-2026-62415, rated critical. What to do about it.

DJ-Classifieds Unauthenticated File Upload

DJ-Classifieds Unauthenticated File Upload

DJ-Classifieds below 3.11.2 let anyone upload files to your Joomla site with no login, and it was being used in the wild. Update to 3.11.2 now.

jDownloads 4.1 Shipped an Unauthenticated Upload Endpoint, Now Fixed in 4.1.6

jDownloads 4.1 Shipped an Unauthenticated Upload Endpoint, Now Fixed in 4.1.6

jDownloads 4.1.0 to 4.1.5 shipped a leftover test script that let anyone upload files to your Joomla site with no login. Update to 4.1.6, which removes it.

Phoca Download 6.1.3 Fixes an Authenticated Upload RCE

Phoca Download 6.1.3 Fixes an Authenticated Upload RCE

Phoca Download for Joomla (com_phocadownload) up to 6.1.2 let a logged-in member upload a PHP file and run code on the server. Fixed in 6.1.3, update now.

RSFiles! Fixes an Unauthenticated File Upload RCE

RSFiles! Fixes an Unauthenticated File Upload RCE

RSFiles! for Joomla (com_rsfiles) up to 1.17.11 had an unauthenticated file upload flaw letting anyone drop a PHP file and run code. Update now.

Balbooa Forms Fixes an Unauthenticated File Upload RCE

Balbooa Forms Fixes an Unauthenticated File Upload RCE

Balbooa Forms (com_baforms) had an unauthenticated file upload RCE, CVE-2026-56291, fixed in 2.4.1. Three more security releases followed: update to 2.4.3.2.

PageBuilder CK File Upload RCE - June 2026

PageBuilder CK File Upload RCE - June 2026

PageBuilder CK below 3.6.0 lets anyone upload and run a file on your Joomla site, no login. CVE-2026-56290, CVSS 10.0, exploited in the wild. Update to 3.6.0.

Zero Day Vulnerability Found in iCagenda Joomla Extension

Zero Day Vulnerability Found in iCagenda Joomla Extension

mySites.guru found and confirmed an unauthenticated upload giving remote code execution on Joomla 6 sites running iCagenda. Fixed same-day in 4.0.8.

SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins

SP Page Builder Zero Day Is Being Used to Plant Fake Joomla Admins

An unauthenticated upload in the SP Page Builder Joomla extension gives remote code execution and creates hidden Super User accounts. Fixed in 6.6.2.

Browse every article