• Project: Joomla!
  • SubProject: CMS
  • Impact: High
  • Severity: Low
  • Probability: Low
  • Versions: 1.0.0-5.4.7,6.0.0-6.1.2
  • Exploit type: Unrestricted Upload of File with Dangerous Type
  • Reported Date: 2026-07-29
  • Fixed Date: 2026-08-18
  • CVE Number: CVE-2026-73373

Description

The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.

Affected Installs

Joomla! CMS versions 1.0.0-5.4.7, 6.0.0-6.1.2

Solution

Upgrade to version 5.4.8, 6.1.3

Contact

The JSST at the Joomla! Security Centre.

Reported By:  Valentin Lobstein (Chocapikk)