CVE-2026-57827

rsfiles\!: Unrestricted Upload of File with Dangerous Type (CVE-2026-57827)

criticalPoCEPSS 2.3%

Affected

  • rsjoomla/rsfiles\! lt *..1.17.12

Description

Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Affected products

The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.

rsjoomlarsfiles\!
1.17.12fixed from 1.17.12

Metrics

10.0
Source: nvd-v4
83.0 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
critical
PoC (publicly reported)
2.3 %
Moderate — model estimates 1-10% exploitation likelihood.
Published
2026-07-11 10:16 UTC
CWE-434

Weakness classes (CWE)

  • CWE-434Base

    Unrestricted Upload of File with Dangerous Type

    The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.

    cwe.mitre.org →

References & sources

Reanalysis & status changes

Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.

  1. CVE Modified2026-07-23 16:17 UTC· security@joomla.org
    • Description: The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. → Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.

Linked advisories