Security Advisory
CVE-2026-57828
8.8
HIGH
Vulnerability Description
Joomla Extension - phoca.cz - Authenticated file upload in RSFiles component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
Published Date
July 11, 2026
Official Source
NIST NVD Advisory