Vulnerability Description
Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows registered users uploading executable files and leads to full RCE.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Phoca | Download | < 6.1.3 |
Related Weaknesses (CWE)
References
- https://mysites.guru/blog/phoca-download-authenticated-file-upload-rce/ExploitThird Party Advisory
- https://www.phoca.cz/phocadownloadProduct
FAQ
What is CVE-2026-57828?
CVE-2026-57828 is a vulnerability with a CVSS score of 8.8 (HIGH). Joomla Extension - phoca.cz - Authenticated file upload in Phoca Downloads component < 6.1.3 - The Joomla extension Phoca Downloads is vulnerable to an authenticated arbitrary file upload that allows ...
How severe is CVE-2026-57828?
CVE-2026-57828 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-57828?
Check the references section above for vendor advisories and patch information. Affected products include: Phoca Download.