Affected versions: ≥ 1.0.0 and < 8.3.16
Full advisory: our disclosure post
OrdaSoft OS CCK versions 1.0.0 to 8.3.15 let anyone upload and run PHP on the site with no login. The front-end upload handler (site/uploader.php, reached through the component's normal routing as task=getContent) has no authentication or permission check. It checks the uploaded file's content with a magic-byte MIME test, but the file-extension allow-list that should restrict the saved name was commented out, so the extension is taken straight from the attacker's filename and the file is written under the site's /images folder, where PHP executes it. A file that starts with valid image bytes and has PHP appended passes the check as a .php file. CVE-2026-102427, CVSS 4.0 10.0 Critical. OrdaSoft fixed this in 8.3.16 by enforcing a jpg/jpeg/png/gif/webp extension allow-list. OrdaSoft's Joomla update manifest still advertises 8.3.14, so sites are not offered 8.3.16 automatically: download it from ordasoft.com and install it by hand. The Pro edition shares the element; its fixed version could not be confirmed. If you cannot update, disable the component, and check /images/com_os_cck*/original/ for any .php file.
Affected versions: ≥ 1.0.0 and < 8.3.16
Official record: cve.org · NVD
Every connected Joomla site is checked against this rule on each audit, and flagged if it runs an affected version.
The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.
10.0 Critical
CVSS 4.0, scored by Joomla CNACVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:YAffected versions: ≥ 1.0.0 and < 8.3.16
Full advisory: our disclosure post
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
Rules current as of 30 September 2026.