Security Advisory

CVE-2026-57828

8.8
HIGH

Vulnerability Description

Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
Published Date July 11, 2026
Official Source NIST NVD Advisory