Description
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.
Published: 2026-07-20
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Joomla extension DJ-Classifieds contains an unauthenticated file upload flaw that permits any visitor to upload arbitrary files, including executable scripts, which the application serves directly. This weakness, classified as CWE-434, effectively gives attackers full remote code execution capability on the affected server.

Affected Systems

DJ-Classifieds, the Joomla extension from dj-extensions.com, is impacted in all releases prior to version 3.11.2.

Risk and Exploitability

The flaw carries a CVSS score of 10, indicating maximum severity. Exploitation requires unauthenticated access to the upload endpoint. The EPSS score is below 1 %, reflecting a low current exploitation likelihood, but the high severity and absence of protective controls present a significant risk if the vulnerability remains unpatched. The vulnerability is not listed in the CISA KEV catalog, yet the potential for widespread abuse remains high should an attacker target a site running the affected extension.

Generated by OpenCVE AI on August 3, 2026 at 01:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update DJ-Classifieds to version 3.11.2 or newer.
  • Disable or restrict the upload feature within DJ-Classifieds if it is not required, limiting allowed file types to non‑executable content.
  • Reconfigure the server and Joomla settings so that uploaded files are stored outside the web document root or given permissions that prevent execution of uploaded code.

Generated by OpenCVE AI on August 3, 2026 at 01:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Dj-extensions.com
Dj-extensions.com dj-classifieds Extension For Joomla
Vendors & Products Dj-extensions.com
Dj-extensions.com dj-classifieds Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE. Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2 - The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.

Tue, 21 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Description The Joomla extension DJ-Classifieds is vulnerable to an unauthenticated file upload, leading to full RCE.
Title Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-Classifieds < 3.11.2
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Dj-extensions.com Dj-classifieds Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:58:24.757Z

Reserved: 2026-07-09T13:39:11.897Z

Link: CVE-2026-61424

cve-icon Vulnrichment

Updated: 2026-07-21T12:34:29.220Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T01:15:03Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type