Unauthenticated Remote Code Installation in Joomla Extension from lomart.fr
CVE-2026-97163
10CRITICAL
What is CVE-2026-97163?
The UP plugin for Joomla, developed by lomart.fr, is susceptible to an unauthenticated remote code installation vulnerability. This allows malicious actors to exploit the plugin versions 5.0.0 through 5.2.0 and 6.0.0 through 6.0.29, potentially leading to unauthorized access and execution of arbitrary code on the affected Joomla sites. Site administrators are advised to apply security patches and update the plugin to mitigate the risk associated with this vulnerability.
Affected Version(s)
UP plugin for Joomla 5.0.0-5.2.0
UP plugin for Joomla 6.0.0-6.0.29
