HIGHVulnerability

CVE-2026-57828

Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.

Properties

severity
HIGH
score
8.8
cve_id
CVE-2026-57828
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
published_at
2026-07-11T10:16:35.710
last_modified
2026-08-19T15:17:12.173

Related Entities (3)

HAS_WEAKNESS (1)

[Weakness]Unrestricted Upload of File with Dangerous Type

DESCRIBED_BY (1)

[Source]NVD

AFFECTS_PRODUCT (1)

[Product]

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-57828 — Ninja Signal Threat Intelligence | Ninja Signal