Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-60032: Joomla JMedia Extension Allows Malicious File Uploads

CVE-2026-60032 CVE-2026-60032
Summary

The JMedia extension in Joomla allows authorized users to upload any type of file, potentially allowing attackers to execute malicious code on the server. This is a serious issue because it can lead to unauthorized access and data breaches. To fix this, update the JMedia extension to version 1.6.0 or later.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
themexpert.com jmedia extension for joomla 1.0-1.5.4
Original title
Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0
Original description
The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.
Vulnerability type
CWE-434 Unrestricted File Upload
Published: 20 Jul 2026 · Updated: 21 Jul 2026 · First seen: 20 Jul 2026