PT-2026-61680 · Joomla · Jmedia

CVE-2026-60033

·

Published

2026-07-20

·

Updated

2026-07-20

CVSS v4.0

5.1

Medium

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions JMedia versions prior to 1.6.0
Description The JMedia extension for Joomla contains a Server-Side Request Forgery (SSRF) flaw. This issue allows a remote-URL download feature to be used to target internal or reserved network addresses, potentially exposing internal services.
Recommendations Update JMedia to version 1.6.0 or later.

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-60033

Affected Products

Jmedia