Description
Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0
Published: 2026-07-29
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability allows an attacker who can access the Joomla site to create directories without authentication. The flaw stems from improper access control in the RO CSVI extension, identified as CWE‑284.

Affected Systems

Any installation of the RO CSVI extension from rolandd.com running Joomla, with affected versions older than 9.11.0.

Risk and Exploitability

The CVSS score is 7.5, indicating a moderate to high severity. The EPSS score is less than 1 %, suggesting a very low likelihood of exploitation at present, and the issue is not listed in the CISA KEV catalog. The flaw can be exploited from the web application without user authentication.

Generated by OpenCVE AI on August 2, 2026 at 07:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the RO CSVI extension to version 9.11.0 or newer to eliminate the vulnerable code path.
  • Remove or restrict web‑server write permissions on the extension’s configuration and upload directories so that only trusted system accounts can create directories.
  • Enable comprehensive logging of file system changes in Joomla and the web server, monitor for unexpected directory creation events, and quarantine any suspicious files immediately.

Generated by OpenCVE AI on August 2, 2026 at 07:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Wed, 29 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Rolandd.com
Rolandd.com ro Csvi Extension For Joomla
Vendors & Products Rolandd.com
Rolandd.com ro Csvi Extension For Joomla

Wed, 29 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0
Title Joomla Extension - rolandd.com - Unauthenticated directory creation RO CSVI < 9.11.0
Weaknesses CWE-284
References

Subscriptions

Rolandd Ro Csvi
Rolandd.com Ro Csvi Extension For Joomla
cve-icon MITRE

Status: PUBLISHED

Assigner: Joomla

Published:

Updated: 2026-07-29T17:41:24.347Z

Reserved: 2026-07-23T16:45:51.220Z

Link: CVE-2026-65943

cve-icon Vulnrichment

Updated: 2026-07-29T15:53:33.888Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-29T13:19:11.087

Modified: 2026-08-05T18:38:15.443

Link: CVE-2026-65943

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T08:00:04Z

Weaknesses