SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-60034

CRITICAL · CVSS 9.4 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The JMedia extension for Joomla versions prior to 1.6.0 is susceptible to a stored cross-site scripting (XSS) vulnerability due to unsanitized SVG file uploads being served without the 'nosniff' header. This flaw allows authenticated users to execute arbitrary scripts in the context of other users, potentially compromising sensitive data and user sessions. Joomla site administrators and developers using this extension should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-60034
Severity
CRITICAL
CVSS
9.4
EPSS
0.25%

Original NVD Description

Joomla Extension - themexpert.com - Authenticated stored XSS in JMedia Extension < 1.6.0 - The Joomla extension JMedia is vulnerable to a stored XSS vulnerability. Unsanitised SVG uploads served without nosniff, leading to stored/reflected XSS.