Vulnerability Bulletins

CVE-2026-57828

   
Affected software JOOMLA
 
The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

Link:

https://nvd.nist.gov/vuln/detail/CVE-2026-57828