PT-2026-77200 · Joomla · Joomla!

·

CVE-2026-73373

·

Published

2026-08-18

·

Updated

2026-09-04

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Joomla! Core versions 1.0.0 through 5.4.7 Joomla! Core versions 6.0.0 through 6.1.2
Description The software fails to include SHTML files in its default list of dangerous files, allowing unrestricted uploads of these files. On servers configured to execute SHTML files, this can lead to remote code execution.
Recommendations Update Joomla! Core versions 1.0.0 through 5.4.7 to a version newer than 5.4.7. Update Joomla! Core versions 6.0.0 through 6.1.2 to a version newer than 6.1.2.

Fix

Unrestricted File Upload

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BIT-JOOMLA-2026-73373
CVE-2026-73373

Affected Products

Joomla!