CVE-2026-60032

CVE-2026-60032CVE-2026-60032

Description

The Joomla extension JMedia is vulnerable to an authenticated arbitrary file upload, leading to RCE. Executable uploads/writes possible (incl. polyglot filenames); chmod didn't strip execute bits.

Scoring

Last modified2026-07-20
Sourced from NVD. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.