OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-97161

CRITICAL · CVSS 9.2 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The UP plugin extension for Joomla versions 5.0.0 to 5.2.0 and 6.0.0 to 6.0.29 is vulnerable to multiple path traversal and file access vulnerabilities, allowing attackers to access sensitive files on the server. This critical flaw, with a CVSS score of 9.2, poses a significant risk to any Joomla installations using the affected plugin, making it essential for administrators to prioritize immediate updates or mitigations. Organizations relying on this extension should urgently assess their systems to prevent potential exploitation.

CVE
CVE-2026-97161
Severity
CRITICAL
CVSS
9.2
EPSS
0.42%

Original NVD Description

Joomla Extension - lomart.fr - Various path traversal / file access vectors in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29