Unrated severityNVD Advisory· Published Jul 20, 2026· Updated Jul 23, 2026
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6
CVE-2026-61900
Description
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6 - The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
Affected products
1- Range: <4.1.6
Patches
Vulnerability mechanics
References
2- mysites.guru/blog/jdownloads-4-1-unauthenticated-upload-flaw/mitrethird-party-advisory
- www.jdownloads.commitreproduct
News mentions
0No linked articles in our index yet.