CVE-2026-84048EPSS p40.9%
CVE-2026-84048CVE-2026-84048
Description
Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attacker control. Code execution requires non-standard server configuration.
Scoring
| EPSS | 0.50% probability of exploitation · percentile 40.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-19 |