CVE-2026-57827
Critical · CVSS 9.8RSFiles (Joomla extension) — Unauthenticated arbitrary file upload leading to Remote Code Execution (RCE)
- CVSS
- 9.8
- nvd
- EPSS
- 0.33%
- 26th pct
- KEV
- No
- Class
- other
- CWE-434
Description
Joomla Extension - rsjoomla.com - Unauthenticated file upload in RSFiles component < 1.17.12 - The Joomla extension RSFiles is vulnerable to an unauthenticated arbitrary file upload that allows uploading executable files and leads to full RCE.
Search profile — drives PoC discovery
Symbols RSFilescom_rsfilesrsjoomlafile uploadexecutable uploadwebshell uploadJoomla download manager
Keywords CVE-2026-57827RSFilesJoomla RSFiles exploitRSFiles unauthenticated file uploadRSFiles RCECWE-434 Joomlarsjoomla file upload vulnerabilityJoomla download manager RCERSFiles PoCarbitrary file upload Joomla extension
Versions: <UNKNOWN>
Ranked PoCs (1) — best first
Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.
- ★ 3
Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.
References
Status: enriched · ingested 2026-07-15T00:00:20.000Z · profiled 2026-07-15T00:30:20.000Z