Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-61900: Joomla JDownloads allows unauthenticated file upload
CVE-2026-61900
Summary
The JDownloads extension for Joomla websites allows hackers to upload any file without a password. This means they can install malware or take full control of the website. To stay safe, update the JDownloads extension to the latest version and use strong passwords.
Original title
The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
Original description
The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
nvd CVSS4.0
10.0
Vulnerability type
CWE-434
Unrestricted File Upload
Published: 20 Jul 2026 · Updated: 20 Jul 2026 · First seen: 20 Jul 2026