Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.0
CVE-2026-57828: Joomla Phoca Downloads RSFiles Component Allows Malicious File Upload
CVE-2026-57828
CVE-2026-57828
Summary
The Joomla Phoca Downloads extension's RSFiles component has a security issue that allows a registered user to upload malicious files. This could allow an attacker to take full control of the website, which could lead to data theft or other security risks. To fix this, update the RSFiles component to version 6.1.3 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| phoca.cz | phoca.cz phoca download extension for joomla | 1.0-6.1.2 |
Original title
The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
Original description
The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
nvd CVSS4.0
9.0
Vulnerability type
CWE-434
Unrestricted File Upload
Published: 11 Jul 2026 · Updated: 20 Jul 2026 · First seen: 11 Jul 2026