Critical severity9.8NVD Advisory· Published Aug 18, 2026· Updated Sep 3, 2026
CVE-2026-73373
CVE-2026-73373
Description
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
2Patches
Vulnerability mechanics
References
2- developer.joomla.org/security-centre/1077-20260810-core-unrestricted-uploads-of-shtml-files.htmlnvdVendor Advisory
- www.joomla.orgnvdProduct
News mentions
1- Joomla: 17 Vulnerabilities Disclosed, Including Critical Code & SQL Injection FlawsVypr Intelligence · Aug 19, 2026