Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
10.0

CVE-2026-61424: DJ-Classifieds Joomla Extension Allows Unauthenticated File Upload

CVE-2026-61424
Summary

The DJ-Classifieds Joomla extension has a security flaw that allows anyone to upload files without a password. This means an attacker can potentially take control of the website and execute any malicious code. To fix this, update the extension to the latest version or remove it if possible.

Original title
The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.
Original description
The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.
nvd CVSS4.0 10.0
Vulnerability type
CWE-434 Unrestricted File Upload
Published: 20 Jul 2026 · Updated: 20 Jul 2026 · First seen: 20 Jul 2026