VYPR

com_joomlaupdate

by Joomla

Source repositories

CVEs (3)

  • CVE-2026-73327HigAug 12, 2026
    risk 0.42cvss 7.6epss 0.01

    Joomla 6.1.1 contains a path traversal vulnerability in the com_joomlaupdate extension that allows a Super User to be induced into extracting a crafted archive containing directory traversal sequences or absolute paths in ZIP entry filenames. Attackers can supply malicious ZIP…

  • CVE-2019-12764MedJun 11, 2019
    risk 0.42cvss 6.5epss 0.01

    An issue was discovered in Joomla! before 3.9.7. The update server URL of com_joomlaupdate can be manipulated by non Super-Admin users.

  • CVE-2026-23898HigApr 1, 2026
    risk 0.40cvss 7.2epss 0.00

    Lack of input validation leads to an arbitrary file deletion vulnerability in the autoupdate server mechanism.