Vulnerability Description
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Joomla | Joomla\! | >= 1.0.0, < 5.4.8 |
Related Weaknesses (CWE)
References
- https://developer.joomla.org/security-centre/1077-20260810-core-unrestricted-uplVendor Advisory
- https://www.joomla.org/Product
FAQ
What is CVE-2026-73373?
CVE-2026-73373 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these fil...
How severe is CVE-2026-73373?
CVE-2026-73373 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-73373?
Check the references section above for vendor advisories and patch information. Affected products include: Joomla Joomla\!.