Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.2

CVE-2026-66914: SEBLOD for Joomla - Unauthenticated File Access

CVE-2026-66914 CVE-2026-66914
Summary

An unauthenticated attacker can access and download files from your Joomla website. This is a serious issue because it allows an attacker to potentially steal sensitive information or disrupt your site's functionality. To protect your site, update SEBLOD to the latest version or remove it if you're no longer using it.

What to do

No fix is available yet. Check with your software vendor for updates.

Affected software
VendorProductAffected versions
seblod.com seblod extension for joomla 1.0.0-3.29.0
Original title
Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.
Original description
Joomla Extension - seblod.com - Unauthenticated path traversal in SEBLOD < 3.30.0, < 4.7.0, < 6.0.1 - An unauthenticated attacker could download files from both inside and outside the webroot.
nvd CVSS4.0 9.2
Vulnerability type
CWE-22 Path Traversal
Published: 7 Aug 2026 · Updated: 7 Aug 2026 · First seen: 7 Aug 2026