CVE-2026-73373

Summary

Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

Affected Software

VendorProductVersion RangeStatus
Joomla! ProjectJoomla! CMS1.0.0-5.4.6affected
Joomla! ProjectJoomla! CMS6.0.0-6.1.2affected
Joomla! ProjectJoomla! Framework Filesystem package1.0.0-3.3.0affected
Joomla! ProjectJoomla! Framework Filesystem package4.0.0-4.2.0affected

Weaknesses

  • CWE-434: CWE-434 Unrestricted Upload of File with Dangerous Type

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References