DJ-Classifieds
Affected versions: < 3.11.2
Full advisory: dj-extensions.com
DJ-Classifieds by DJ-Extensions, all versions before 3.11.2, exposes a front-end file upload endpoint (task=imageupload) that requires no login and validates no CSRF token. An anonymous visitor can write an attacker-named file into the component upload directory, which on a default install is served over the web. Several mitigations were already present in older builds and do reduce the impact: an extension blacklist rejects .php, .phtml, .sh and .js, uploaded content is scanned for patterns such as "<?php", "eval(" and "base64", image extensions are validated with getimagesize(), and temporary files are cleaned up after roughly 12 hours. The content scan only matches the literal "<?php" opening tag, so a short-tag payload ("<?=") survives it, which leaves a polyglot image webshell stored intact and executable on permissive hosts or through a local file inclusion chain. Version 3.11.2 (released 20 July 2026) adds authentication and CSRF/session checks to the imageupload endpoint and enforces a server-side image-only whitelist. Update to 3.11.2 or later. If you cannot update immediately, block POST requests to index.php?option=com_djclassifieds&task=imageupload at the web server or WAF, and check the component upload directory for files you do not recognise. This range also covers the earlier authenticated SQL injection fixed in 3.10.2 (CVE-2025-54474).
The base metrics as Joomla CNA published them, and what each one means for a site running an affected version. Threat and environmental metrics are left out: they describe a moment or a particular install rather than the flaw.
10.0 Critical
CVSS 4.0, scored by Joomla CNACVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:HDJ-Classifieds
Affected versions: < 3.11.2
Full advisory: dj-extensions.com
Updating for CVE-2026-61424 alone can leave a site on a release another rule still matches. These are the other flaws we check for in the same extension.
A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.
This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.
Rules current as of 5 October 2026.