AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-66914

CRITICAL · CVSS 9.2 EPSS 0.38%

Source: NVD + CISA KEV + EPSS · Published 2026-08-07 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The SEBLOD Joomla extension versions prior to 3.30.0, 4.7.0, and 6.0.1 are vulnerable to an unauthenticated path traversal attack, allowing attackers to download arbitrary files from the server. This critical vulnerability poses a significant risk as it can expose sensitive information and system files, potentially leading to further exploitation. Joomla administrators and users of the SEBLOD extension should prioritize updating to the latest versions to mitigate this risk.

CVE
CVE-2026-66914
Severity
CRITICAL
CVSS
9.2
EPSS
0.38%

Original NVD Description

Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.