Description

The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

Severity (CVSS)

Base score9
SeverityCritical
VersionCVSS 4.0
VectorCVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Provided byCNA

Weaknesses

  • CWE-434 — CWE-434: Unrestricted Upload of File with Dangerous Type

Affected products

VendorProductVersions
phoca.czphoca.cz Phoca Download extension for Joomla1.0-6.1.2

References

Authoritative sources

This page is a snapshot. For the latest enrichment and updates, view the record on CVE.org or the NVD.

Generated from the official CVE List on 12 Jul 2026 07:01 UTC.