Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
9.4
CVE-2026-60032: Joomla JMedia Extension Allows Malicious File Uploads
CVE-2026-60032
CVE-2026-60032
Summary
The JMedia extension in Joomla allows authorized users to upload any type of file, potentially allowing attackers to execute malicious code on the server. This is a serious issue because it can lead to unauthorized access and data breaches. To fix this, update the JMedia extension to version 1.6.0 or later.
What to do
No fix is available yet. Check with your software vendor for updates.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| themexpert.com | jmedia extension for joomla | 1.0-1.5.4 |
Original title
Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0
Original description
The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.
Vulnerability type
CWE-434
Unrestricted File Upload
Published: 20 Jul 2026 · Updated: 21 Jul 2026 · First seen: 20 Jul 2026