UP Universal Plugin (plg_content_up) 5.0.0 to 6.0.29 - Unauthenticated Remote Code Installation, File Read, SQL Injection and PHP Injection (CVE-2026-97160, CVE-2026-97161, CVE-2026-97162, CVE-2026-97163)
UP (the Universal Plugin for Joomla, plg_content_up) versions 5.0.0 to 6.0.29 have several flaws found and reported by mySites.guru. Unauthenticated: a request to Joomla's AJAX endpoint could trigger installation of action code from GitHub with TLS checks disabled (CVE-2026-97163, CVSS 4.0 10.0), read arbitrary files including configuration.php and create files outside the intended folder (CVE-2026-97161, 9.2), plus SQL injection vectors (CVE-2026-97162, 8.3). The PHP and SQL actions reserved to administrators could be reached by article authors through action-name variants (PHP command injection, CVE-2026-97160, 9.4). Fixed in UP 6.1.0 (Joomla 5.2 to 6.x) and UP 5.2.1 (Joomla 3.10 to 5.1), released 26 Sep 2026. Update to the fixed release for your Joomla version; if you cannot, disable the plugin. Check the plugin folder for action directories or PHP files you did not add.
Affected versions: ≥ 5.0.0 and < 5.2.1
Full advisory: our disclosure post