SEPTEMBER 7, 2026
Live Feed
Back to database
Case File

CVE-2026-62415

CRITICAL · CVSS 9.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-21 · Last synced 2026-08-20

CyberRota Analysis

AI-Generated

The Membership Pro extension for Joomla, prior to version 4.6.2, is vulnerable due to an insecure default configuration that permits unauthenticated users to upload media assets. This flaw could lead to unauthorized access and potential exploitation of the web application, posing a critical risk to the integrity and security of affected systems. Organizations using this extension should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-62415
Severity
CRITICAL
CVSS
9.1
EPSS
0.27%

Original NVD Description

Joomla Extension - joomdonation.com - Insecure default configuration Membership Pro < 4.6.2 - The Joomla extension Membership Pro prior version 4.6.2 did by default allow unauthenticated users to upload media assets.