CVE-2026-57827
CRITICAL 10.0EPSS 2.3%
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
- CVSS v4.0
- 10.0 CRITICAL
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:A/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:Y/R:X/V:X/RE:X/U:Red - CVSS v3.1
- 9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - EPSS
- 2.33% chance of exploitation in the next 30 days, 82th percentile
- Nuclei
- critical · CWE-434
- Published
- 2026-07-11
- Updated
- 2026-08-12
Proof-of-concept exploits (5)
- shinthink/CVE-2026-5782715★ · 2026-07-29
- Mohammad-008/rsfiles-CVE-2026-578279★ · 2026-08-03
- Candisexterior171/CVE-2026-578270★ · 2026-08-31
- jjkk123123/CVE-2026-578271★ · 2026-08-06
- g0d150ne/CVE_2026_578270★ · 2026-08-10