Unauthenticated File Upload Vulnerability in Joomla Extension JDownloads
CVE-2026-61900

10CRITICAL

Key Information:

Vendor
CVE Published:
20 July 2026

What is CVE-2026-61900?

The JDownloads extension for Joomla possesses a vulnerability that allows unauthenticated users to upload arbitrary files. This flaw can lead to remote code execution, posing significant security risks to affected systems. Administrators are urged to take immediate action by updating to the latest secured version and implementing best practices for file uploads to protect their environments.

Affected Version(s)

jDownloads extension for Joomla 4.1.0-4.1.5

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Andrés Restrepo
.