← Back to browse · API

CVE-2026-57827

Severity
CRITICAL
CVSS
10.0
EPSS
0.00405
Risk score
40.14
CISA KEV
No
PoC
Yes
Published
2026-07-11
Modified
2026-08-12
First seen
2026-08-05
Aliases
EUVD-2026-43168, GHSA-7Q98-WG4P-5V7G
Products
rsjoomla.com:rsjoomla.com RSFiles extension for Joomla 1.0-1.17.11, rsjoomla:rsfiles\!
Sources
nvd CVE-2026-57827
github 229545582cef5a16c7648609|CVE-2026-57827
github d4a1ffc91d20f0bfab57c3ed|CVE-2026-57827
github 809922280c4897aedc5fc2f2|CVE-2026-57827
euvd EUVD-2026-43168
github 7be807eea37d9dc991e943b5|CVE-2026-57827

Description

Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

References