CVE-2026-57828
phoca.cz phoca.cz Phoca Download extension for Joomla, download
Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
- CVSS
- 9
- EPSS
- 0.30% 22.5% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.11