SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-57828

HIGH · CVSS 8.8 EPSS 0.37%

Source: NVD + CISA KEV + EPSS · Published 2026-07-11 · Last synced 2026-08-10

CyberRota Analysis

AI-Generated

The Phoca Downloads extension for Joomla versions prior to 6.1.3 is vulnerable to an authenticated arbitrary file upload, enabling registered users to upload executable files. This flaw can lead to remote code execution, posing a significant risk to the integrity and security of the affected systems. Organizations using this extension should prioritize immediate remediation to mitigate potential exploitation.

CVE
CVE-2026-57828
Severity
HIGH
CVSS
8.8
EPSS
0.37%

Original NVD Description

Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

Related CVEs

Other vulnerabilities affecting the same vendor(s)