πŸ” CVE Alert

CVE-2026-61900

UNKNOWN 0.0

Joomla Extension - dj-extensions.com - Unauthenticated arbitrary file upload in DJ-jDownloads < 4.1.6

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The Joomla extension JDownloads is vulnerable to an unauthenticated file upload, leading to full RCE.

CWE CWE-434
Vendor dj-extensions.com
Product jdownloads extension for joomla
Published Jul 20, 2026
Stay Ahead of the Next One

Get instant alerts for dj-extensions.com jdownloads extension for joomla

Be the first to know when new unknown vulnerabilities affecting dj-extensions.com jdownloads extension for joomla are published β€” delivered to Slack, Telegram or Discord.

Get Free Alerts β†’ Free Β· No credit card Β· 60 sec setup

Affected Versions

dj-extensions.com / jDownloads extension for Joomla
4.1.0-4.1.5

References

NVD β†— CVE.org β†— EPSS Data β†—
jdownloads.com: https://www.jdownloads.com/ mysites.guru: https://mysites.guru/blog/jdownloads-4-1-unauthenticated-upload-flaw/

Credits

AndrΓ©s Restrepo