Unauthenticated Remote Code Installation in Joomla Extension from lomart.fr
CVE-2026-97163

10CRITICAL

Key Information:

Vendor

Lomart.fr

Vendor
CVE Published:
26 September 2026

What is CVE-2026-97163?

The UP plugin for Joomla, developed by lomart.fr, is susceptible to an unauthenticated remote code installation vulnerability. This allows malicious actors to exploit the plugin versions 5.0.0 through 5.2.0 and 6.0.0 through 6.0.29, potentially leading to unauthorized access and execution of arbitrary code on the affected Joomla sites. Site administrators are advised to apply security patches and update the plugin to mitigate the risk associated with this vulnerability.

Affected Version(s)

UP plugin for Joomla 5.0.0-5.2.0

UP plugin for Joomla 6.0.0-6.0.29

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Phil Taylor, mysites.guru
.