CVE-2026-61900
Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.
| CWE | CWE-434 |
| Vendor | dj-extensions.com |
| Product | jdownloads extension for joomla |
| Published | Jul 20, 2026 |
Stay Ahead of the Next One
Get instant alerts for dj-extensions.com jdownloads extension for joomla
Be the first to know when new unknown vulnerabilities affecting dj-extensions.com jdownloads extension for joomla are published β delivered to Slack, Telegram or Discord.
Get Free Alerts β
Free Β· No credit card Β· 60 sec setup
Affected Versions
dj-extensions.com / jDownloads extension for Joomla
4.1.0-4.1.5
References
Credits
AndrΓ©s Restrepo