CRITICAL 9.8 CVE-2026-73373 Published 18 Aug 2026

Joomla Core SHTML File Upload Code Execution Vulnerability

Worried this affects one of your servers?

Joomla! Core is affected by an unrestricted upload of SHTML files vulnerability. The default list of dangerous files did not include SHTML files.

On servers that executed these files, this could lead to code execution.

  • Affected versions: Joomla 1.0.0-5.4.7 and 6.0.0-6.1.2

Reference: CVE-2026-73373 on NVD

← Back to Security News