CVE-2026-73373

EUVD-2026-61026
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.8 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 49.24%
Affected Products (NVD)
VendorProductVersion
joomlajoomla\!
1.0.0 ≤
𝑥
< 5.4.8
joomlajoomla\!
6.0.0 ≤
𝑥
< 6.1.3
𝑥
= Vulnerable software versions