File Upload Vulnerability in Easy Discuss for Joomla by Stack Ideas
CVE-2026-21625

4.8MEDIUM

Key Information:

Vendor
CVE Published:
16 January 2026

What is CVE-2026-21625?

The Easy Discuss component for Joomla has a vulnerability that arises from inadequate validation of user-provided uploads. The component only verifies file uploads based on their extensions, neglecting to perform any checks on the MIME types of the files. This oversight could allow malicious users to upload harmful files, posing a significant risk to the security of Joomla sites. Web administrators are encouraged to implement additional validation measures to mitigate the risks associated with unverified file inputs.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

EasyDiscuss extension for Joomla 1.0.0-5.0.15

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

simoni
Swiss Paraplegic Research
.