CVE-2026-61900
10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Summary
The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| dj-extensions.com | jDownloads extension for Joomla | 4.1.0-4.1.5 | affected |
Weaknesses
- CWE-434: CWE-434 Unrestricted Upload of File with Dangerous Type
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.