Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-57827: Joomla RSFiles Extension Allows Unauthenticated File Upload

CVE-2026-57827 CVE-2026-57827
Summary

The RSFiles extension in Joomla allows unauthorized users to upload any type of file, including executable files. This can lead to hackers gaining full control over the website. Update to the latest version of the RSFiles extension (1.17.12 or higher) to fix this issue.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
rsjoomla.com rsjoomla.com rsfiles extension for joomla 1.0-1.17.11
Original title
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
Original description
The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
nvd CVSS4.0 10.0
Vulnerability type
CWE-434 Unrestricted File Upload
Published: 11 Jul 2026 · Updated: 20 Jul 2026 · First seen: 11 Jul 2026