Description
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Published: 2026-07-11
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Joomla extension RSFiles has a flaw that permits attackers to upload arbitrary files without authentication. The flaw allows executable code to be stored and later executed, giving an attacker full remote code execution capabilities. This weakness is classified as CWE-434, an untrusted upload vulnerability.

Affected Systems

The vulnerability affects the RSFiles extension for Joomla from rsjoomla.com, versions earlier than 1.17.12. Users running those older releases are exposed.

Risk and Exploitability

The CVSS score climbs to 10, indicating a critical severity. The EPSS score is <1%, a very low but nonzero probability that attackers exploit this vulnerability, though the potential impact remains high. The vulnerability is not listed in the CISA KEV catalog. The likely attack path is via the public web interface of the extension, where an unauthenticated user can submit files for upload and execute them on the server.

Generated by OpenCVE AI on July 31, 2026 at 12:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade RSFiles to version 1.17.12 or newer as soon as possible.
  • Until the upgrade can be applied, block external access to the upload functionality using web‑server configuration or a firewall rule to prevent unauthenticated requests.
  • Implement stricter server‑side validation that rejects non‑image uploads or remove the upload feature entirely if it is not required.

Generated by OpenCVE AI on July 31, 2026 at 12:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Rsjoomla
Rsjoomla rsfiles Extension For Joomla
Vendors & Products Rsjoomla
Rsjoomla rsfiles Extension For Joomla

Sat, 11 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Title Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/AU:Y/U:Red'}


Subscriptions

Rsjoomla Rsfiles Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T15:01:02.375Z

Reserved: 2026-06-25T16:55:04.093Z

Link: CVE-2026-57827

cve-icon Vulnrichment

Updated: 2026-07-13T15:43:06.923Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T12:45:03Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type