Description
Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
Published: 2026-07-11
Score: 9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Patch Immediately
AI Analysis

Impact

The Joomla extension Phoca Downloads, version earlier than 6.1.3, permits authenticated users to upload arbitrary files. Because the component does not restrict file types, an attacker can upload executable scripts that are processed by the web server, thus achieving full remote code execution on the Joomla site and the underlying web server. This vulnerability is a file upload flaw, classified as CWE‑434.

Affected Systems

The flaw affects sites running the Phoca Download extension for Joomla provided by phoca.cz, specifically any installation of the component older than version 6.1.3. Any Joomla website that has this extension installed and allows registered users to upload files is at risk. The vulnerability is not listed in the CISA KEV catalog.

Risk and Exploitability

The CVSS score of 9 indicates critical severity. The EPSS score of < 1 % shows a very low likelihood of exploitation, although the attack requires only authenticated access to the site’s upload interface. The likely attack vector is an authenticated user exploiting the upload feature of the Phoca Downloads component to place a malicious file on the server which is then executed with the web server’s privileges.

Generated by OpenCVE AI on August 22, 2026 at 11:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the Phoca Downloads component to version 6.1.3 or newer, which removes the unrestricted file‑type check.
  • Reconfigure the component to restrict allowed file extensions to safe types (e.g., only images or documents) and limit upload permissions to the minimum trusted administrators.
  • If an upgrade is not immediately possible, disable or uninstall the Phoca Downloads extension until a patched version can be applied.

Generated by OpenCVE AI on August 22, 2026 at 11:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 19 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE. Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
Title Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE. Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

Mon, 13 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 13 Jul 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Phoca
Phoca phoca Download Extension For Joomla
Vendors & Products Phoca
Phoca phoca Download Extension For Joomla

Sat, 11 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
Title Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Phoca Download Phoca Download Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-08-19T14:44:19.013Z

Reserved: 2026-06-25T16:55:04.094Z

Link: CVE-2026-57828

cve-icon Vulnrichment

Updated: 2026-07-13T15:42:39.313Z

cve-icon NVD

Status : Modified

Published: 2026-07-11T10:16:35.710

Modified: 2026-08-19T15:17:12.173

Link: CVE-2026-57828

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-22T11:30:17Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type