OCTOBER 6, 2026
Live Feed
Back to database
Case File

CVE-2026-97163

CRITICAL · CVSS 10 EPSS 0.42%

Source: NVD + CISA KEV + EPSS · Published 2026-09-26 · Last synced 2026-10-06

CyberRota Analysis

AI-Generated

The UP plugin extension for Joomla versions 5.0.0 to 5.2.0 and 6.0.0 to 6.0.29 is vulnerable to unauthenticated remote code installation, allowing attackers to execute arbitrary code on affected systems without authentication. This critical vulnerability poses a severe risk to any Joomla sites using these versions, potentially leading to complete system compromise. Joomla administrators and web developers should prioritize immediate updates or mitigations to protect their environments.

CVE
CVE-2026-97163
Severity
CRITICAL
CVSS
10
EPSS
0.42%

Original NVD Description

Joomla Extension - lomart.fr - Unauthenticated remote code installation in UP plugin extension 5.0.0-5.2.0, 6.0.0-6.0.29