Description
Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.
Published: 2026-07-20
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The JMedia extension for Joomla allows authenticated users to upload arbitrary files, including executable and polyglot types, because the upload handler does not strip execute bits. This flaw can be leveraged by an attacker who has Joomla administrative or content‑manager privileges to upload malicious code that the web server then executes, giving the attacker full control over the host. The vulnerability is classified as a high‑severity file‑upload issue (CWE‑434).

Affected Systems

The flaw affects the JMedia extension for Joomla developed by themexpert.com in all versions earlier than 1.6.0. Sites running Joomla with this extension version are vulnerable and may have administrators or other authenticated users capable of uploading files.

Risk and Exploitability

The CVSS score of 9.4 reflects the high impact and availability of the vulnerability. The EPSS score of < 1% indicates a very low probability of exploitation at this time, and the issue is not listed in the CISA KEV catalog, implying no currently known exploits. The attack requires authenticated access to the Joomla backend; an attacker with such privileges can directly place a web‑accessible file that the server will execute. Because the flaw permits uploading of any file type without restriction and the server is likely configured to serve files from the upload directory, the exploitation path is straightforward and does not rely on additional infrastructure.

Generated by OpenCVE AI on August 3, 2026 at 01:17 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the JMedia extension to version 1.6.0 or later.
  • Restrict the file upload directory on the web server and disable execution of files in that directory using .htaccess or web‑server configuration directives.
  • Configure the extension to validate uploaded file types strictly, allowing only approved image formats and rejecting polyglot filenames to prevent accidental execution.

Generated by OpenCVE AI on August 3, 2026 at 01:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Themexpert.com
Themexpert.com jmedia Extension For Joomla
Vendors & Products Themexpert.com
Themexpert.com jmedia Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits. Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.

Mon, 20 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 18:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.
Title Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Themexpert.com Jmedia Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:55:23.506Z

Reserved: 2026-07-08T05:31:35.890Z

Link: CVE-2026-60032

cve-icon Vulnrichment

Updated: 2026-07-20T20:13:56.207Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:30:16Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type