What the vulnerability does
01Description
Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
Explanation of Vulnerability in Simple Terms
02Summary
The Phoca Download extension for Joomla contains an unrestricted file upload vulnerability. An authenticated user with low privileges can upload arbitrary files to the server, potentially including executable code. This allows an attacker to run their own code on the site and compromise the entire Joomla installation. The vulnerability affects versions 1.0-6.1.2.
What an attacker can do
03Attacker Capabilities
Upload arbitrary files, including executable code, to the server.
Potential impact on your site
04Site Impact
An authenticated attacker can run code on your site and take full control of your Joomla installation.
Conditions required to exploit
05Prerequisites
Attacker must have a low-privilege Joomla user account.
Key dates
06Disclosure timeline
July 11, 2026
CVE published
July 23, 2026
Record updated