SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-60033

MEDIUM · CVSS 5.1 EPSS 0.23%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The JMedia extension for Joomla versions prior to 1.6.0 is susceptible to a Server-Side Request Forgery (SSRF) vulnerability, allowing attackers to exploit remote URL downloads to access internal or reserved network addresses. This could lead to unauthorized access to sensitive resources within the affected systems. Joomla administrators and users of the JMedia extension should prioritize this vulnerability to mitigate potential risks to their network security.

CVE
CVE-2026-60033
Severity
MEDIUM
CVSS
5.1
EPSS
0.23%

Original NVD Description

Joomla Extension - themexpert.com - SSRF via remote download in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to an SSRF vulnerability. Remote-URL download could target internal/reserved addresses.