CVE-2026-73373
published 2026-08-18CVE-2026-73373: Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML…
PriorityP354critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.36%
29.9th percentile
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| joomla!_project | joomla!_cms | — | — |
| joomla!_project | joomla!_cms | — | — |
| joomla!_project | joomla!_framework_filesystem_package | — | — |
| joomla!_project | joomla!_framework_filesystem_package | — | — |
| joomla | joomla_! | >= 1.0.0 < 5.4.8 | 5.4.8 |
| joomla | joomla_! | >= 6.0.0 < 6.1.3 | 6.1.3 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv4.08.9HIGHCVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Joomla! Project Joomla! CMS/Joomla! Framework Filesystem package up to 5.4.7/6.1.2 SHTML file unrestricted upload (WID-SEC-2026-2926)
vuldb·2026-09-06·CVSS 9.8
CVE-2026-73373 [CRITICAL] Joomla! Project Joomla! CMS/Joomla! Framework Filesystem package up to 5.4.7/6.1.2 SHTML file unrestricted upload (WID-SEC-2026-2926)
A vulnerability, which was classified as critical, was found in Joomla! Project Joomla! CMS and Joomla! Framework Filesystem package up to 5.4.7/6.1.2. This affects an unknown function of the component SHTML file Handler. The manipulation results in unrestricted upload.
This vulnerability is identified as CVE-2026-73373. The attack can be executed remotely. There is not any exploit available.
GHSA
GHSA-38c6-5ffm-cv2j: Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1
ghsa_unreviewed·2026-08-18
CVE-2026-73373 [HIGH] CWE-434 GHSA-38c6-5ffm-cv2j: Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1
Joomla! Core - [20260810] - Unrestricted uploads of SHTML files in Joomla 1.0.0-5.4.7, 6.0.0-6.1.2 - The default list of dangerous files did not include SHTML files. On servers that executed these files, that could lead to code execution.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-08-18
Published