CVE-2026-57827

The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Scoring

Severity
CRITICAL
CVSS base score
10
CVSS vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red
EPSS probability
2.33%
CWE
CWE-434
Published
2026-07-11
Last modified
2026-08-12

Affected products

Weakness type

Related vulnerabilities

Markdown version · Browse all CVEs