CVE-2026-57827
rsfiles\!: Unrestricted Upload of File with Dangerous Type (CVE-2026-57827)
Affected
- rsjoomla/rsfiles\!
lt *..1.17.12
Description
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Affected products
The following versions are affected. Older releases of the same product line are also vulnerable unless stated otherwise.
rsjoomlarsfiles\!
1.17.12fixed from 1.17.12Metrics
83.0 %
Critical — this CVE ranks in the top fifth of all CVEs scored today (rank ≥ 80%).
Show all metrics
Severity
critical
127.05
PoC (publicly reported)
9.8
10.0
Published
2026-07-11 10:16 UTC
CWE-434
Weakness classes (CWE)
CWE-434Base
Unrestricted Upload of File with Dangerous Type
The product allows the upload or transfer of dangerous file types that are automatically processed within its environment.
cwe.mitre.org →
References & sources
Reanalysis & status changes
Chronological NVD audit events for this CVE — reanalyses, CVSS updates, CPE diffs.
- CVE Modified2026-07-23 16:17 UTC· security@joomla.org
- Description: The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE. → Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.