Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-57827: Joomla RSFiles Extension Allows Unauthenticated File Upload
CVE-2026-57827
CVE-2026-57827
Summary
The RSFiles extension in Joomla allows unauthorized users to upload any type of file, including executable files. This can lead to hackers gaining full control over the website. Update to the latest version of the RSFiles extension (1.17.12 or higher) to fix this issue.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| rsjoomla.com | rsjoomla.com rsfiles extension for joomla | 1.0-1.17.11 |
Original title
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
Original description
The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
nvd CVSS4.0
10.0
Vulnerability type
CWE-434
Unrestricted File Upload
Published: 11 Jul 2026 · Updated: 20 Jul 2026 · First seen: 11 Jul 2026