CVE-2026-60032 CRITICAL

CVE-2026-60032: Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0

Vendor Themexpert.com
Product JMedia extension for Joomla
Weakness CWE-434 · Unrestricted file upload
Published July 20, 2026
Last update July 23, 2026

CVSS base score

9.4/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

Joomla Extension - themexpert.com - Authenticated arbitrary file upload in JMedia < 1.6.0 - The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.

Explanation of Vulnerability in Simple Terms

02Summary

The JMedia extension for Joomla contains an unrestricted file upload vulnerability that allows high-privilege users to upload arbitrary files to the server. An attacker with administrative or elevated permissions can exploit this to upload malicious files, potentially leading to remote code execution. Sites running affected versions should update immediately.

What an attacker can do

03Attacker Capabilities

Upload arbitrary files to the server, potentially including executable code.

Potential impact on your site

04Site Impact

A compromised admin account or insider threat could upload malware or backdoors, leading to full site compromise.

Conditions required to exploit

05Prerequisites

Attacker must have high-level privileges (admin or equivalent role) in Joomla.

Key dates

06Disclosure timeline

July 20, 2026 CVE published
July 23, 2026 Record updated

Related vulnerabilities

08Related CVE