CVE-2026-73373
Joomla! Project Joomla! CMS, Joomla! Framework Filesystem package
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
- CVSS
- 8.9
- EPSS
- - - percentile
- CISA KEV
- Not listed
- Published
- 2026.08.19