Skip to main content
mySites.guru
J!Awards 2026mySites.guru is shortlisted for Your Favourite Tool in Your Joomla WorkflowVote by 11 OctoberHow to vote

RSFiles! security vulnerabilities

mySites.guru tracks 1 vulnerability in RSFiles! (com_rsfiles), covering 2 CVEs. Every connected Joomla site is checked against it on each audit.

Is my site affected?

Your site is affected if it runs RSFiles! in this range:

  • up to and including 1.17.11
Latest safe version
The rules here cover more than one release line, so there is no single version that clears all of them. Use the fixed release listed for the line your site runs.
What to do
Update to the fixed release listed for your version in the table below, or to the newest release from the vendor. Where a range has no fix recorded, check the vendor's release notes before keeping RSFiles! installed.

Every RSFiles! vulnerability we track

Newest first. CVSS is the score published in each CVE record, where it has one; the severity column is the rating our check uses.

CVEAffected versionsFixed inSeverityAdded
CVE-2026-57827CVSS 10.0CVE-2025-50057CVSS 6.9up to and including 1.17.11after 1.17.11Critical2026-07-10

What we check for

RSFiles! (com_rsfiles) <= 1.17.11 - Unauthenticated Arbitrary File Upload (RCE)

RSFiles! (com_rsfiles) version 1.17.11 and earlier contain an arbitrary file upload flaw in the front-end upload handler that leads to remote code execution. The file-type allow-list and the upload permission check run in a separate pre-flight step, while the method that actually writes the file trusts an attacker-supplied filename and never re-validates the extension, so a .php web shell can be written into the web-served download folder and executed. On builds up to 1.17.11 this is exploitable without any authentication. RSJoomla released a patched build on 2026-07-10 that is STILL numbered 1.17.11 (the version string was not bumped); it only closes the unauthenticated path. A residual bypass remains that lets any user permitted to upload (and any anonymous visitor on sites that allow public uploads) still write an executable .php. Because the version number is unchanged, every install reporting 1.17.11 or lower must be treated as affected. No fixed version is available yet - the issue has been reported to the vendor and a follow-up release is awaited. Mitigation until then: restrict RSFiles uploads to trusted user groups only, or disable uploads entirely (set Enable Upload to No), or turn on the extension's Secure Download Folder option so a .htaccess disables PHP execution in the download folder. Also covered by this rule: CVE-2025-50057, an unauthenticated denial of service via the RSFiles! search feature in 1.16.3 to 1.17.7.

Affected versions: ≤ 1.17.11

Full advisory: www.rsjoomla.com

Timeline

  1. 18 July 2025CVE-2025-50057 record published
  2. 10 July 2026Check added for CVE-2026-57827 and CVE-2025-50057 (up to and including 1.17.11)
  3. 10 July 2026We published: RSFiles! Fixes an Unauthenticated File Upload RCE
  4. 11 July 2026CVE-2026-57827 record published

What we have written about RSFiles!

References

Each CVE page above links its official cve.org record and its NVD entry.

RSFiles! vulnerability questions

Which versions of RSFiles! are vulnerable?
mySites.guru tracks one vulnerability in RSFiles! (com_rsfiles). A site is affected if its installed version is in this range: up to and including 1.17.11.
What is the latest safe version of RSFiles!?
The rules here cover more than one release line, so there is no single version that clears all of them. Use the fixed release listed for the line your site runs.
How do I check which version of RSFiles! my Joomla site runs?
The installed version is listed on the Joomla administrator's Extensions: Manage screen; search it for com_rsfiles. mySites.guru reads the installed version on every audit of a connected site and checks it against this rule.

Running RSFiles! on a site you manage?

A free audit tells you which of your Joomla and WordPress sites run an affected version, which are out of date, and which have not been backed up. No card required. If a site is already compromised, fix.mysites.guru is a single fixed fee per incident, usually resolved the same day.

This check is part of the mySites.guru Joomla vulnerability scanner, which reads every installed extension's version on each audit. Browse the rest of the Joomla vulnerability database.

CVE identifiers: CVE-2026-57827, CVE-2025-50057. Rules current as of 5 October 2026.