OS CCK (com_os_cck) below 8.3.16 - Unauthenticated Arbitrary File Upload (RCE)
OrdaSoft OS CCK versions 1.0.0 to 8.3.15 let anyone upload and run PHP on the site with no login. The front-end upload handler (site/uploader.php, reached through the component's normal routing as task=getContent) has no authentication or permission check. It checks the uploaded file's content with a magic-byte MIME test, but the file-extension allow-list that should restrict the saved name was commented out, so the extension is taken straight from the attacker's filename and the file is written under the site's /images folder, where PHP executes it. A file that starts with valid image bytes and has PHP appended passes the check as a .php file. CVE-2026-102427, CVSS 4.0 10.0 Critical. OrdaSoft fixed this in 8.3.16 by enforcing a jpg/jpeg/png/gif/webp extension allow-list. OrdaSoft's Joomla update manifest still advertises 8.3.14, so sites are not offered 8.3.16 automatically: download it from ordasoft.com and install it by hand. The Pro edition shares the element; its fixed version could not be confirmed. If you cannot update, disable the component, and check /images/com_os_cck*/original/ for any .php file.
Affected versions: ≥ 1.0.0 and < 8.3.16
Full advisory: our disclosure post