SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-61424

CRITICAL · CVSS 10 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-07-20 · Last synced 2026-08-19

CyberRota Analysis

AI-Generated

The DJ-Classifieds Joomla extension prior to version 3.11.2 is susceptible to unauthenticated arbitrary file uploads, which can be exploited to achieve full remote code execution (RCE). This vulnerability poses a significant risk to any Joomla installations using the affected extension, allowing attackers to execute malicious code on the server. Organizations utilizing DJ-Classifieds should prioritize immediate updates to mitigate potential exploitation.

CVE
CVE-2026-61424
Severity
CRITICAL
CVSS
10
EPSS
0.26%

Original NVD Description

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.