CVE-2017-7989: Joomla!

Medium severity, CVSS 6.5. EPSS: 1% chance of exploitation in the next 30 days.

In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.

Affected products

  • Joomla! Joomla!: version 3.2.0 only; version 3.2.1 only; version 3.2.2 only; version 3.2.3 only; version 3.2.4 only; version 3.3.0 only; …

Published 2017-04-25. Last modified 2026-06-17.