CVE-2026-84048EPSS p40.9%

CVE-2026-84048CVE-2026-84048

Description

Joomla Extension - joomgalleryfriends.net - Unauthenticated arbitrary file upload via the TUS endpoint in JoomGallery < 4.4.2 - The TUS endpoint allows arbitrary file uploads, however neither file name nor file extension are under attacker control. Code execution requires non-standard server configuration.

Scoring

EPSS0.50% probability of exploitation · percentile 40.9% · 2026-10-05T12:00:23Z
Last modified2026-09-19
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.