← Back

CVE-2026-57828

nvd nist
Published: Jul 11, 2026Modified: Jul 14, 2026

JSON object

Loading...
9.0
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Show more
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XShow less
Source: security@joomla.org (Secondary)

Description

The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

Affected (1)

Products: Phoca: Download
1 product
Download
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Before 6.1.3

References (2)

Source: security@joomla.org
ExploitThird Party Advisory
Source: security@joomla.org
Product

Timeline

No history available yet.