Description
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
Published: 2026-07-20
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Joomla extension JDownloads by dj-extensions.com enables attackers to upload arbitrary files without authentication via the public upload interface. The uploaded file is then executed with the same privileges as the web application, granting full remote code execution on the site. This issue is a classic uncontrolled file upload vulnerability, identified as CWE‑434.

Affected Systems

All releases of the jDownloads extension from dj-extensions.com before version 4.1.6 are vulnerable. The flaw exists in the extension distributed for Joomla and is present in every pre‑4.1.6 build. Upgrading to 4.1.6 or later removes the vulnerability.

Risk and Exploitability

The CVSS score of 10 indicates a critical impact, and the EPSS score of <1% suggests a relatively low but non‑zero likelihood of exploitation. The flaw is not listed in CISA’s KEV catalog, yet its high severity and simple exploitation path make it attractive to attackers. The vulnerability can be triggered from any network location that can access the Joomla site’s public upload interface, providing an unauthenticated and externally visible attack vector.

Generated by OpenCVE AI on August 4, 2026 at 05:59 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the jDownloads extension to version 4.1.6 or later.
  • Restrict the upload handler to allow only whitelisted file extensions and MIME types.
  • Configure the web server or application firewall to block unauthenticated access to the upload endpoint and monitor upload activity for suspicious patterns.

Generated by OpenCVE AI on August 4, 2026 at 05:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Dj-extensions.com
Dj-extensions.com jdownloads Extension For Joomla
Vendors & Products Dj-extensions.com
Dj-extensions.com jdownloads Extension For Joomla

Thu, 23 Jul 2026 15:45:00 +0000

Type Values Removed Values Added
Description The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE. Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

Tue, 21 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 20 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Description The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
Title Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6
Weaknesses CWE-434
References
Metrics cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Dj-extensions.com Jdownloads Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-23T14:58:00.984Z

Reserved: 2026-07-12T05:35:55.728Z

Link: CVE-2026-61900

cve-icon Vulnrichment

Updated: 2026-07-21T16:37:15.991Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T06:00:05Z

Weaknesses
  • CWE-434

    Unrestricted Upload of File with Dangerous Type