Authenticated PHP Command Injection Vulnerability in Joomla Extension by Lomart
CVE-2026-97160

9.4CRITICAL

Key Information:

Vendor

Lomart.fr

Vendor
CVE Published:
26 September 2026

What is CVE-2026-97160?

A vulnerability has been identified in the UP plugin for Joomla, which is due to an authenticated, privileged PHP command injection. This flaw exists in versions 5.0.0 through 5.2.0 and 6.0.0 through 6.0.29. Attackers with valid credentials may exploit this vulnerability to execute arbitrary PHP commands on the server, compromising the website's security and potentially allowing unauthorized access to sensitive data.

Affected Version(s)

UP plugin for Joomla 5.0.0-5.2.0

UP plugin for Joomla 6.0.0-6.0.29

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.