Unauthenticated File Upload Vulnerability in DJ-Classifieds from DJ Extensions
CVE-2026-61424

10CRITICAL

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-61424?

The DJ-Classifieds extension from DJ Extensions contains a vulnerability that allows an unauthenticated user to upload malicious files. This loophole can lead to full remote code execution (RCE), posing significant risks to web applications using this extension. The issue must be addressed promptly to prevent potential exploitation in both personal and commercial environments. Reference materials provide additional insights into the implications of this vulnerability.

Affected Version(s)

DJ-Classifieds extension for Joomla 1.0-3.11.1

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor
.