CVE-2026-61900 CRITICAL

CVE-2026-61900: Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6

Vendor Dj-Extensions.com
Product jDownloads extension for Joomla
Weakness CWE-434 · Unrestricted file upload
Published July 20, 2026
Last update July 23, 2026

CVSS base score

10.0/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

What the vulnerability does

01Description

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

Explanation of Vulnerability in Simple Terms

02Summary

The jDownloads extension for Joomla contains an unrestricted file upload vulnerability in versions 4.1.0 through 4.1.5. An attacker can upload arbitrary files to the server without authentication or user interaction. This allows execution of malicious code on the site with full system access. All sites running affected versions require immediate patching.

What an attacker can do

03Attacker Capabilities

Upload and execute arbitrary files on the server, gaining full control of the site.

Potential impact on your site

04Site Impact

Complete site compromise: attacker can read/modify/delete all data, create admin accounts, or use the server for further attacks.

Conditions required to exploit

05Prerequisites

Network access only; no authentication or user interaction required.

Key dates

06Disclosure timeline

July 20, 2026 CVE published
July 23, 2026 Record updated

Related vulnerabilities

08Related CVE